Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard
A company is implementing a new application that will be hosted in Azure. This application needs to securely access Azure Key Vault to retrieve secrets and Azure SQL Database to store data. The security team requires that the application authenticates to these Azure services using its own identity, without requiring hardcoded credentials or secrets to be stored within the application's code or configuration. Which type of managed identity should be assigned to the application?
- ASystem-assigned managed identity
- BService principal with certificate
- CUser-assigned managed identity
- DApplication registration with client secret
Show answer & explanationAnswer & explanation
Correct answer: A. System-assigned managed identity
A system-assigned managed identity is created and managed by Azure for a specific Azure resource (like a VM, App Service, or AKS pod). Its lifecycle is tied to the resource, and it automatically authenticates to Azure AD, allowing the application to access other Azure services securely without managing credentials.
Why the other options are wrong
- B. Service principal with certificate also requires certificate management, which the requirement aims to avoid by using managed identities.
- C. User-assigned managed identities are created independently and can be assigned to multiple resources, but for a single application's dedicated identity, system-assigned is often simpler.
- D. Application registration with a client secret requires managing the secret, which the requirement explicitly seeks to avoid.
System-assigned Managed Identity
An identity created and managed by Azure that is directly tied to a specific Azure resource (e.g., a Virtual Machine, Azure App Service). Its lifecycle is linked to the resource, and it allows the resource to authenticate to Azure AD and access other Azure services securely.
- Automatically created and deleted with the resource.
- Cannot be shared with other resources.
- Eliminates the need for developers to manage credentials.
Memory trick: Managed Identities: Azure's keymaster, no secrets needed.