Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy
A company is implementing a security policy that mandates all workload identities must have their credentials rotated automatically every 90 days. This applies to both system-assigned and user-assigned managed identities. What is the primary mechanism Azure uses to ensure the automatic rotation of credentials for managed identities?
- AAzure Policy deploys a remediation task to rotate credentials every 90 days.
- BAzure AD automatically handles the rotation of credentials for managed identities.
- CAzure Key Vault automatically rotates secrets stored for managed identities.
- DAzure AD CredentialLifetimePolicy is configured for each managed identity.
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD automatically handles the rotation of credentials for managed identities.
For managed identities (both system-assigned and user-assigned), Azure AD automatically handles the creation, rotation, and deletion of the credentials (certificates) used by these identities. This is a core benefit of managed identities, eliminating manual credential management.
Why the other options are wrong
- A. Azure Policy is for enforcing rules, but the actual rotation mechanism for managed identities is built into Azure AD, not a policy-triggered remediation.
- C. Key Vault is a place to store secrets, but it's not the mechanism that rotates managed identity credentials.
- D. CredentialLifetimePolicy applies to application registrations/service principals, not directly to managed identities themselves; managed identities have built-in rotation.
Managed Identity Credential Rotation
The automatic process by which Azure AD securely rotates the underlying credentials (certificates) used by managed identities to authenticate to Azure AD.
- Fully automated by Azure AD.
- Eliminates the need for manual credential management.
- Enhances security by ensuring credentials are short-lived and frequently renewed.
- Applies to both system-assigned and user-assigned managed identities.
Memory trick: Managed Identity: Azure handles the keys, no worries, just automation!