Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionEasy
A developer is building a new application that will run on an Azure Virtual Machine (VM). The application needs to securely access Azure Key Vault to retrieve secrets without requiring hardcoded credentials or managing service principal secrets. Which identity solution should the developer implement for the VM?
- ASystem-assigned managed identity
- BUser-assigned managed identity
- CService principal with a client secret
- DApplication registration with certificates
Show answer & explanationAnswer & explanation
Correct answer: A. System-assigned managed identity
A system-assigned managed identity provides an identity for an Azure service (like a VM) in Azure AD. This identity is tied to the lifecycle of the VM and can be used to authenticate to Azure Key Vault without requiring the developer to manage any credentials or secrets.
Why the other options are wrong
- B. A user-assigned managed identity can also be used, but a system-assigned one is simpler when the identity is exclusively for a single resource and tied to its lifecycle.
- C. Requires managing and rotating client secrets, which the scenario explicitly wants to avoid.
- D. Requires managing and rotating certificates, which is similar to managing secrets and is what the scenario aims to avoid.
System-assigned Managed Identity
An identity created and managed by Azure for an Azure resource (e.g., VM, App Service). Its lifecycle is tied to the resource.
- Automatically registered with Azure AD.
- No credentials to manage.
- Ideal for single resource authentication to other Azure services.
Memory trick: Managed identities are secret-free, System is tied, User is shared.