Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A developer is building an Azure Function App that needs to securely access data stored in an Azure SQL Database. The Function App should authenticate to the SQL Database without storing any credentials (like connection strings with username/password) in its code or configuration files. The solution must follow the principle of least privilege. What is the most secure and recommended method for the Function App to authenticate to the Azure SQL Database?
- AConfigure a system-assigned managed identity for the Function App.
- BUse a shared access signature (SAS) token for the SQL Database.
- CGrant the Function App's service principal direct Contributor access to the SQL Database.
- DStore the SQL Database credentials in Azure Key Vault and retrieve them at runtime.
Show answer & explanationAnswer & explanation
Correct answer: A. Configure a system-assigned managed identity for the Function App.
A system-assigned managed identity provides an automatically managed identity for an Azure service in Azure AD. This identity can then be granted specific RBAC permissions to other Azure resources, such as an Azure SQL Database, allowing the Function App to authenticate without needing to manage any secrets. This aligns with the principle of least privilege and avoids credential storage.
Why the other options are wrong
- B. SAS tokens are primarily for storage accounts, not Azure SQL Databases, and would still require managing the token.
- C. Granting Contributor access is excessive privilege. Managed identities allow granting specific data reader/writer roles to the SQL database, adhering to least privilege.
- D. While Key Vault is good for storing secrets, using a managed identity is more secure as it removes the need to store and rotate any secret, even in Key Vault, for the Function App itself.
Managed Identities
Azure Managed Identities provide an automatically managed identity in Azure AD for Azure services, enabling them to authenticate to other Azure services without needing to store credentials in code.
- Eliminates credential management for developers.
- Supports system-assigned and user-assigned types.
- Authenticates via Azure AD, adhering to RBAC.
Memory trick: Managed Identity: Your service's ID card, no password needed.