Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard
A developer needs to deploy an Azure Function App that requires access to a Storage Account. The Function App should authenticate to the Storage Account without using hardcoded credentials or secrets. Which Azure AD feature should the developer configure for the Function App?
- AAzure AD B2C
- BManaged Identities for Azure Resources
- CService Principals (manual creation)
- DAzure AD Application Proxy
Show answer & explanationAnswer & explanation
Correct answer: B. Managed Identities for Azure Resources
Managed Identities for Azure Resources (formerly Managed Service Identity) allow Azure services to authenticate to Azure AD and access other Azure resources (like Storage Accounts) securely, without the need for developers to manage credentials. The Function App will automatically get an identity in Azure AD.
Why the other options are wrong
- A. Azure AD B2C (Business-to-Consumer) is for customer identity and access management, not for Azure service-to-service authentication.
- C. While a service principal can be used, 'manual creation' implies managing secrets, which the requirement explicitly aims to avoid. Managed Identities automate this securely.
- D. Azure AD Application Proxy provides secure remote access to on-premises web applications, unrelated to Azure service authentication.
Managed Identities for Azure Resources
A feature of Azure Active Directory that provides Azure services with an automatically managed identity in Azure AD, allowing them to authenticate to services that support Azure AD authentication without managing credentials.
- Eliminates hardcoded credentials/secrets.
- Two types: System-assigned and User-assigned.
- Used for Azure service-to-service authentication.
Memory trick: Managed Identities are like robots getting their own secure ID cards from Azure AD.