Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
An organization is deploying a custom application to an Azure virtual machine (VM). The application needs to query Azure AD for user information. You want to ensure that the application can authenticate to Azure AD with the least amount of administrative overhead and without requiring manual credential updates. Which type of Managed Identity should you configure for the VM?
- AUser-assigned managed identity, manually attached to the VM.
- BSystem-assigned managed identity, enabled directly on the VM.
- CSystem-assigned managed identity, created as a separate resource.
- DUser-assigned managed identity, assigned via an Azure AD group.
Show answer & explanationAnswer & explanation
Correct answer: B. System-assigned managed identity, enabled directly on the VM.
A system-assigned managed identity is enabled directly on an Azure resource (like a VM) and its lifecycle is tied to that resource. It provides an identity that can authenticate to Azure AD and other Azure services without manual credential management, addressing the requirement for least administrative overhead and no manual credential updates.
Why the other options are wrong
- A. User-assigned managed identities require a separate creation step and then explicit assignment to the VM, increasing initial overhead compared to system-assigned.
- C. System-assigned managed identities are not created as separate resources; they are an integral part of the resource they are assigned to.
- D. User-assigned managed identities cannot be assigned via an Azure AD group; they are assigned directly to resources.
System-assigned Managed Identity
A type of Managed Identity that is created and deleted with the Azure resource it's associated with, providing a unique identity for that specific resource to authenticate to Azure AD.
- Lifecycle tied to the Azure resource.
- Enabled directly on the resource.
- Cannot be shared among multiple resources.
- Simplifies credential management for a single resource.
Memory trick: System Stays, User Shares.