Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is implementing a new Azure-hosted application that needs to securely retrieve secrets from Azure Key Vault without storing any credentials in the application's code or configuration files. The application's lifecycle is tied to a specific Azure App Service instance. Which type of identity should be used for this application?

  1. AApplication registration with a certificate
  2. BService principal with a client secret
  3. CUser-assigned managed identity
  4. DSystem-assigned managed identity
Show answer & explanation

Correct answer: D. System-assigned managed identity

A system-assigned managed identity is automatically created and managed by Azure for a specific Azure resource, like an App Service. It's ideal when the identity's lifecycle is tied to the resource it represents and avoids credential management.

Why the other options are wrong

  • A. Application registrations with certificates still involve managing certificate lifecycles and are not as seamless as managed identities for this use case.
  • B. Service principals with client secrets require manual secret management, which the requirement explicitly avoids.
  • C. User-assigned managed identities are standalone resources, useful for multiple resources or when the identity needs a separate lifecycle.

System-Assigned Managed Identity

A type of managed identity automatically created and managed by Azure, tied directly to the lifecycle of a single Azure resource, allowing it to authenticate to other Azure services.

  • Tied to a single Azure resource (e.g., VM, App Service).
  • Automatically created and deleted with the resource.
  • No credentials to manage in code.

Memory trick: Managed identities: Azure's robots for secure service access.

More Implement an identity management solution questions