Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A new Azure Function App is deployed to host several serverless functions. These functions need to authenticate to Azure Key Vault to retrieve database connection strings and also write logs to an Azure Storage Account. The functions are deployed as part of a single Function App resource. You need to configure the most secure and manageable identity solution for this scenario.

  1. ACreate a user-assigned managed identity, assign it to the Function App, and grant it permissions to Key Vault and Storage Account.
  2. BEmbed the Key Vault access keys and Storage Account connection strings directly into the function code.
  3. CCreate an Azure AD application registration with a client secret, store the secret in the Function App's configuration, and grant permissions.
  4. DEnable a system-assigned managed identity for the Function App and grant it permissions to Key Vault and Storage Account.
Show answer & explanation

Correct answer: D. Enable a system-assigned managed identity for the Function App and grant it permissions to Key Vault and Storage Account.

Since all functions are deployed within a single Function App resource and share the same identity requirements, a system-assigned managed identity is the most secure and manageable choice. It's automatically tied to the Function App's lifecycle, eliminating manual credential management and providing a clear scope of permissions.

Why the other options are wrong

  • A. While a user-assigned managed identity would work, a system-assigned one is simpler when a single resource needs an identity, as it's automatically managed and tied to the resource's lifecycle.
  • B. Embedding secrets directly into code is a major security vulnerability and should never be done.
  • C. This involves manual credential management (client secret) and storing it, which is less secure and less manageable than managed identities.

System-Assigned MI for Function Apps

Enabling a system-assigned managed identity for an Azure Function App, allowing the functions within it to securely authenticate to other Azure services without managing credentials.

  • Identity is created and deleted with the Function App.
  • Automatic credential management by Azure.
  • Ideal for single-resource identity needs.
  • Simplifies secure access to services like Key Vault, Storage, Cosmos DB.

Memory trick: Function App's built-in identity: simple, secure, no secrets to hold.

More Implement and manage workload identities questions