Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A new Azure Function App is deployed to host several serverless functions. These functions need to authenticate to Azure Key Vault to retrieve connection strings and API keys. The security team mandates that the authentication mechanism must not rely on any secrets stored in environment variables or code. Additionally, the functions should inherit permissions based on their hosting environment. Which identity configuration should you recommend for the Azure Function App?

  1. ACreate a user-assigned managed identity and attach it to the Function App.
  2. BUse an Azure AD user account and store its credentials in the Function App settings.
  3. CCreate an application registration with a client secret and store the secret in Key Vault.
  4. DEnable a system-assigned managed identity for the Function App.
Show answer & explanation

Correct answer: D. Enable a system-assigned managed identity for the Function App.

Enabling a system-assigned managed identity for the Azure Function App provides an automatically managed identity that is tied to the lifecycle of the Function App. It allows the functions to authenticate to Azure Key Vault without storing any secrets in code or environment variables, and its permissions are granted directly to this identity, aligning with the 'inherit permissions based on their hosting environment' implicitly.

Why the other options are wrong

  • A. While a user-assigned managed identity also avoids stored secrets, a system-assigned identity is simpler for a single resource like a Function App when granular sharing is not explicitly required, and it inherently 'inherits' its identity from the hosting environment.
  • B. Using a user account and storing its credentials directly contradicts the requirement of 'not rely on any secrets stored in environment variables or code'.
  • C. Storing a client secret (even in Key Vault) still involves managing a secret, which the question aims to avoid for the application's direct authentication.

System-assigned Managed Identity for Function Apps

An identity automatically created for an Azure Function App, enabling it to authenticate to other Azure services without managing credentials, and its lifecycle is tied to the Function App.

  • Eliminates credential storage in code/config.
  • Automatically managed by Azure.
  • Lifecycle tied to the Function App.
  • Simplifies securing serverless applications.

Memory trick: System Security Simplifies Serverless Secrets.

More Implement and manage workload identities questions