Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A developer is building an Azure Function App that needs to securely retrieve secrets from Azure Key Vault without embedding credentials in the application code. The Function App will be deployed to an App Service Plan. Which identity solution should the developer implement?

  1. AOAuth 2.0 Client Credentials Flow
  2. BAzure AD Application Proxy
  3. CManaged Identity
  4. DService Principal
Show answer & explanation

Correct answer: C. Managed Identity

Managed Identities for Azure resources provide an automatically managed identity in Azure AD for Azure services. This identity can then be granted permissions to access other Azure services (like Key Vault) without the need for developers to manage credentials directly in their code.

Why the other options are wrong

  • A. OAuth 2.0 Client Credentials Flow is an authentication flow, but Managed Identity simplifies its implementation by handling the underlying credential management.
  • B. Azure AD Application Proxy provides secure remote access to on-premises web apps, irrelevant for this scenario.
  • D. A Service Principal is an identity for an application, but requires manual credential management (client secrets or certificates).

Managed Identities for Azure Resources

An Azure AD feature that provides Azure services with an automatically managed identity in Azure AD. This identity can be used to authenticate to any service that supports Azure AD authentication without embedding credentials in code.

  • Eliminates credential management for developers
  • Automatically managed by Azure
  • Two types: System-assigned and User-assigned

Memory trick: Managed Identity is like a 'no-password' pass for Azure services.

More Manage Azure identities and governance questions