Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionEasy

A developer is building a new application that will run on an Azure Virtual Machine (VM). The application needs to securely access Azure Key Vault to retrieve secrets without storing any credentials in the application code or configuration files. Which type of managed identity should the developer configure for the Azure VM?

  1. AUser-assigned managed identity
  2. BSystem-assigned managed identity
  3. CApplication registration with client secret
  4. DService principal with certificate
Show answer & explanation

Correct answer: B. System-assigned managed identity

A system-assigned managed identity is automatically created and managed by Azure for a specific Azure resource (like a VM). It has a lifecycle tied to that resource and is ideal for scenarios where a single resource needs to authenticate to other Azure services without manual credential management.

Why the other options are wrong

  • A. A user-assigned managed identity is a standalone Azure resource that can be assigned to multiple resources, typically used when multiple resources need to share the same identity.
  • C. Using an application registration with a client secret requires managing the secret, which the question explicitly aims to avoid.
  • D. Using a service principal with a certificate also involves managing the certificate, which is what managed identities are designed to eliminate.

System-Assigned Managed Identity

A type of managed identity automatically created and managed by Azure for a specific Azure resource, whose lifecycle is tied to that resource.

  • Automatically provisioned and deleted with the Azure resource.
  • Cannot be shared with other resources.
  • Eliminates the need for developers to manage credentials.
  • Ideal for single resource authentication to other Azure services.

Memory trick: System-assigned is like a built-in ID card for one person, user-assigned is like a shared company ID card.

More Implement an authentication and access management solution questions