Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy
A developer is building an Azure Function App that needs to securely access secrets stored in an Azure Key Vault. The Function App should authenticate to Key Vault without requiring secrets or connection strings in its code or configuration. What authentication method should the developer implement?
- AAzure AD user account with password
- BKey Vault access policy with an application ID
- CManaged Identity for Azure Resources
- DService principal with a client secret
Show answer & explanationAnswer & explanation
Correct answer: C. Managed Identity for Azure Resources
Managed Identities for Azure Resources provides an Azure AD identity for Azure services, eliminating the need for developers to manage credentials in code. The Function App can be assigned a system-assigned or user-assigned managed identity, which Azure automatically authenticates with Key Vault.
Why the other options are wrong
- A. Using a user account and password in code is insecure and goes against best practices for service-to-service authentication.
- B. While Key Vault access policies are used, they define *who* can access, not *how* the Function App authenticates without managing secrets.
- D. Service principals with client secrets require managing the secret, which is what we want to avoid.
Managed Identities for Azure Resources
Managed Identities provide an automatically managed identity in Azure Active Directory (Azure AD) for Azure services, eliminating the need for developers to manage credentials.
- Eliminates credential management in code.
- Azure automatically manages the identity lifecycle.
- Supports system-assigned and user-assigned identities.
- Used for authenticating Azure services to other Azure AD-protected services.
Memory trick: Managed Identity is your 'Secret Keeper' for Azure services, no more manual keys!