Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionEasy
A company is implementing a new application that will be hosted on Azure App Service. This application needs to securely access data stored in Azure Key Vault without storing credentials in its code or configuration files. The company wants to use a managed identity for this purpose. Which type of managed identity should be assigned to the Azure App Service instance to meet this requirement?
- AUser-assigned managed identity
- BService principal managed identity
- CApplication registration managed identity
- DSystem-assigned managed identity
Show answer & explanationAnswer & explanation
Correct answer: D. System-assigned managed identity
A system-assigned managed identity is directly tied to the lifecycle of the Azure resource it's assigned to. When the resource is deleted, the identity is also deleted. This type of identity is automatically created and managed by Azure, making it suitable for a single resource like an Azure App Service requiring secure access to other Azure services.
Why the other options are wrong
- A. User-assigned managed identities are standalone Azure resources that can be assigned to multiple resources, which is not the most direct or simplest solution for a single App Service instance.
- B. Service principal is the underlying object for managed identities, but 'Service principal managed identity' is not a distinct type of managed identity in the Azure UI or documentation.
- C. Application registration is used for applications that need to authenticate users or access resources with their own identity, but it requires manual credential management (client secrets/certificates) and is not a managed identity type.
System-assigned managed identity
A type of Azure AD identity automatically created and managed by Azure for a specific Azure resource, enabling that resource to authenticate to other services securely.
- Tied to the lifecycle of a single Azure resource.
- Automatically created and deleted with the resource.
- No manual credential management required.
Memory trick: Systematic Security for Single Services.