Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company is implementing a new Azure-hosted application that needs to securely retrieve secrets from Azure Key Vault without storing any credentials in the application's code or configuration files. The application's lifecycle is tied to a specific Azure App Service instance. Which type of identity should be used for this application?
- AApplication registration with a certificate
- BService principal with a client secret
- CUser-assigned managed identity
- DSystem-assigned managed identity
Show answer & explanationAnswer & explanation
Correct answer: D. System-assigned managed identity
A system-assigned managed identity is automatically created and managed by Azure for a specific Azure resource, like an App Service. It's ideal when the identity's lifecycle is tied to the resource it represents and avoids credential management.
Why the other options are wrong
- A. Application registrations with certificates still involve managing certificate lifecycles and are not as seamless as managed identities for this use case.
- B. Service principals with client secrets require manual secret management, which the requirement explicitly avoids.
- C. User-assigned managed identities are standalone resources, useful for multiple resources or when the identity needs a separate lifecycle.
System-Assigned Managed Identity
A type of managed identity automatically created and managed by Azure, tied directly to the lifecycle of a single Azure resource, allowing it to authenticate to other Azure services.
- Tied to a single Azure resource (e.g., VM, App Service).
- Automatically created and deleted with the resource.
- No credentials to manage in code.
Memory trick: Managed identities: Azure's robots for secure service access.