Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
A company is migrating several on-premises applications to Azure. These applications currently use Active Directory service accounts for authentication and authorization. After migration, they will run on Azure Virtual Machines and need to authenticate to various Azure AD-protected resources, including Azure SQL Database and Azure Key Vault. The security team wants to define specific permissions for each application that aligns with its least privilege requirements. Which type of workload identity object should be created for each application?
- AAzure AD application registration
- BSystem-assigned managed identity
- CUser-assigned managed identity
- DAzure AD security group
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD application registration
Azure AD application registrations represent applications within Azure AD. They provide an identity that can be used for authentication and authorization, allowing granular permissions (e.g., API permissions, Azure RBAC roles) to be assigned specifically to that application, enforcing least privilege.
Why the other options are wrong
- B. System-assigned managed identities are tied to a single Azure resource's lifecycle and are not ideal for representing distinct 'applications' that might span multiple resources or have complex permission requirements beyond simple resource access.
- C. While user-assigned managed identities provide an identity, application registrations are typically used for applications migrated from on-premises that need their own explicit identity and permissions, especially if they are not solely tied to a single Azure resource like a VM.
- D. Azure AD security groups are used to group users or service principals for permission management, not to represent the identity of an application itself.
Azure AD Application Registration
An object in Azure AD that represents an application, enabling it to be an identity that can authenticate to Azure AD and access protected resources.
- Provides an application's identity in Azure AD.
- Allows defining API permissions and Azure RBAC roles.
- Can be used for client applications (users sign in) or daemon applications (no user interaction).
- Includes properties like Application ID, Redirect URIs, and credentials (secrets/certificates).
Memory trick: App Registration: The official ID card for your application in Azure AD.