Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy
A company is developing a new application that will run on an Azure Virtual Machine (VM). This application needs to access data stored in an Azure Storage Account. The security team has mandated that no secrets or connection strings should be hardcoded in the application. You need to recommend a secure and efficient way for the application to authenticate to the Azure Storage Account.
- ACreate a service principal with a client secret and store the secret in Azure Key Vault, then retrieve it from the VM.
- BEmbed the Storage Account access key directly in the application's configuration file on the VM.
- CCreate an Azure AD application registration, generate a certificate, and use it for authentication.
- DEnable a system-assigned managed identity for the Azure VM and grant it Contributor role on the Storage Account.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable a system-assigned managed identity for the Azure VM and grant it Contributor role on the Storage Account.
Enabling a system-assigned managed identity for the Azure VM allows the VM to authenticate to Azure AD and obtain tokens without managing any credentials itself. This token can then be used to access Azure resources like Storage Accounts, provided the managed identity has the necessary permissions.
Why the other options are wrong
- A. While secure, this involves managing a secret in Key Vault and retrieving it, which is less efficient than managed identities for VM authentication.
- B. Embedding access keys directly is highly insecure and violates the security mandate to avoid hardcoded secrets.
- C. This is a valid authentication method but requires manual certificate management and deployment, making it more complex than managed identities for this scenario.
System-Assigned Managed Identity
A type of managed identity automatically created and deleted with an Azure resource, providing an identity for that resource to authenticate to Azure AD without credential management.
- Tied to the lifecycle of a single Azure resource (e.g., VM, App Service).
- Azure automatically manages its credentials.
- Cannot be shared with other resources.
- Used for authenticating to Azure AD and subsequently accessing other Azure services.
Memory trick: Managed Identities make resource access magic, no keys to track!