Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A developer needs to create an Azure Function App that securely accesses secrets stored in an Azure Key Vault. The Function App should authenticate to Key Vault without storing any credentials in its code or configuration files. What is the most secure and recommended method for the Function App to authenticate to the Key Vault?
- AEnable a system-assigned Managed Identity for the Function App.
- BUse an access key directly from the Key Vault.
- CConfigure a Service Principal with a client secret.
- DStore Key Vault credentials in Function App application settings.
Show answer & explanationAnswer & explanation
Correct answer: A. Enable a system-assigned Managed Identity for the Function App.
Managed Identities for Azure resources provide an automatically managed identity in Azure AD for Azure services, including Function Apps. This allows the Function App to authenticate to services like Key Vault without requiring any credentials to be stored in code or configuration, enhancing security.
Why the other options are wrong
- B. Access keys are directly stored credentials and are not recommended for application authentication due to security risks.
- C. While a Service Principal is an identity, using a client secret means storing a credential, which Managed Identities aim to avoid.
- D. Storing credentials in application settings is insecure as they can be easily compromised if the settings are exposed.
Managed Identities for Azure Resources
An Azure Active Directory feature that provides Azure services with an automatically managed identity in Azure AD, allowing them to authenticate to other services securely without needing to store credentials in code.
- Eliminates the need for credential management (secrets, certificates).
- Two types: system-assigned and user-assigned.
- Enhances security by simplifying authentication to Azure AD-protected services.
Memory trick: Let Azure manage the app's keys, don't store them yourself.