Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy
A company is migrating several on-premises applications to Azure. These applications currently use service accounts for authentication. You need to create an equivalent secure identity in Azure AD for these applications that requires explicit credential management and rotation. Which object type should you provision in Azure AD?
- AAzure AD device object.
- BAzure AD user account.
- CAzure AD application registration with a client secret.
- DManaged Identity for Azure resources.
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD application registration with a client secret.
An Azure AD application registration, specifically configured with a client secret, serves as a non-interactive identity for applications. It requires explicit management of the secret, including rotation, which aligns with the requirement for explicit credential management and rotation for applications not hosted directly in Azure where Managed Identities are applicable.
Why the other options are wrong
- A. Azure AD device objects represent physical or virtual devices, not application identities.
- B. Azure AD user accounts are for human users, not applications, and are managed differently.
- D. Managed Identities are for Azure-hosted resources and do not require explicit credential management, contradicting the requirement.
Azure AD Application Registration
An object in Azure AD that represents an application, allowing it to authenticate to Azure AD and be granted permissions to access other resources.
- Defines how an application interacts with Azure AD.
- Can be configured with client secrets or certificates for authentication.
- Used for both applications hosted in Azure and external applications.
- Has an associated service principal for resource access.
Memory trick: Applications Authenticate with App Registrations and Secrets.