Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy
A developer needs to deploy an Azure Function App that requires access to an Azure Key Vault to retrieve secrets. The Function App should authenticate to Key Vault without storing any credentials in its code or configuration files. Which method should the developer use to achieve this secure authentication?
- AAzure AD application registration with certificate
- BKey Vault access policy with IP address whitelist
- CService Principal with client secret
- DManaged Identity for Azure Resources
Show answer & explanationAnswer & explanation
Correct answer: D. Managed Identity for Azure Resources
Managed Identities for Azure Resources provide an Azure AD identity for Azure services, allowing them to authenticate to other Azure services (like Key Vault) without needing to store credentials. This is the most secure and recommended method.
Why the other options are wrong
- A. While more secure than client secrets, using a certificate still involves managing the certificate lifecycle and deploying it, which is less seamless than Managed Identities.
- B. Key Vault access policy with an IP address whitelist restricts access by network location, but it does not provide an identity for the Function App to authenticate with Key Vault.
- C. Using a Service Principal with a client secret requires storing the secret, which the requirement explicitly avoids.
Managed Identities
Managed Identities for Azure Resources provide an automatically managed identity in Azure Active Directory (Azure AD) for Azure services, allowing them to authenticate to other services securely.
- Eliminates the need for developers to manage credentials.
- Can be system-assigned (tied to a resource) or user-assigned (standalone).
- Provides an Azure AD identity that can be granted RBAC permissions.
Memory trick: Managed Identities handle credentials invisibly, like a secret agent.