Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy

A developer is creating an Azure Function App that needs to securely access secrets stored in an Azure Key Vault. The Function App should authenticate to the Key Vault without requiring any hardcoded credentials or secrets in its code or configuration. Which identity solution should the developer implement for the Function App?

  1. AApplication registration
  2. BService principal
  3. CManaged identity
  4. DAzure AD user account
Show answer & explanation

Correct answer: C. Managed identity

Managed identities for Azure resources provide an automatically managed identity in Azure AD for Azure services. This allows the Function App to authenticate to services like Key Vault without managing credentials.

Why the other options are wrong

  • A. Application registration is the process of registering an application in Azure AD, which then uses a service principal. It still involves credential management.
  • B. A service principal is an identity used by applications or services, but it typically requires manual management of client secrets or certificates.
  • D. An Azure AD user account is for human users, not for Azure services to authenticate to other services.

Managed Identities for Azure Resources

An Azure Active Directory feature that provides Azure services with an automatically managed identity, allowing them to authenticate to other Azure services securely without needing to manage credentials.

  • Eliminates credential management.
  • Integrated with Azure resource lifecycle.
  • Can be system-assigned or user-assigned.

Memory trick: Managed Identity: no secret, no problem.

More Manage Azure identities and governance questions