Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionEasy

A company is migrating its infrastructure to Azure and wants to ensure that Virtual Machines (VMs) can securely access Azure Key Vault to retrieve secrets without requiring hard-coded credentials. The solution must follow the principle of least privilege. What is the most appropriate method to achieve this?

  1. ACreate a shared access signature (SAS) for the Key Vault and embed it in the VM's startup script.
  2. BAssign a system-assigned managed identity to the VM and grant it 'Get' and 'List' permissions on the Key Vault secrets.
  3. CStore Key Vault credentials as environment variables on the VM and configure the application to use them.
  4. DCreate a service principal for the VM, generate a client secret, and store it securely on the VM for Key Vault access.
Show answer & explanation

Correct answer: B. Assign a system-assigned managed identity to the VM and grant it 'Get' and 'List' permissions on the Key Vault secrets.

Managed identities for Azure resources, specifically system-assigned managed identities, provide an identity for Azure services in Azure AD. This allows VMs to authenticate to services like Key Vault without managing credentials. Granting 'Get' and 'List' permissions follows the principle of least privilege for retrieving secrets.

Why the other options are wrong

  • A. SAS tokens are primarily for storage accounts, not Key Vault, and embedding them is not secure.
  • C. Storing credentials as environment variables is less secure and requires manual rotation and management.
  • D. Creating a service principal and managing its client secret manually defeats the purpose of automatic credential management and is less secure than managed identities for Azure resources.

Azure Managed Identities

Azure AD identities automatically managed by Azure, allowing Azure services to authenticate to cloud services without requiring developers to manage credentials.

  • Eliminates the need for hard-coded credentials.
  • Can be system-assigned (tied to a resource's lifecycle) or user-assigned (independent resource).
  • Used for authenticating to any service that supports Azure AD authentication.

Memory trick: Managed identities: Your Azure resources get their own secure keys.

More Implement an authentication and access management solution questions