Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy

An organization is deploying a custom application to an Azure virtual machine (VM). The application needs to authenticate to an Azure SQL Database. The security team insists that the application should not store any credentials (username, password, connection string) directly. The identity solution should be tightly coupled to the VM's lifecycle. Which type of workload identity should be configured?

  1. AAzure AD application registration with client secret
  2. BUser-assigned managed identity
  3. CSystem-assigned managed identity
  4. DAzure AD guest user account
Show answer & explanation

Correct answer: C. System-assigned managed identity

A system-assigned managed identity is automatically created and deleted with the Azure VM. It provides an identity for the VM to authenticate to Azure AD and access other Azure services like Azure SQL Database, without needing to store any credentials in the application or VM configuration.

Why the other options are wrong

  • A. This requires manual secret management and storage, which violates the security requirement of not storing credentials.
  • B. User-assigned managed identities are standalone resources and are not tightly coupled to a single VM's lifecycle; they can be shared.
  • D. Azure AD guest user accounts are for external users, not for Azure resources to authenticate to other Azure services.

System-assigned Managed Identity

An identity created and managed by Azure, tied directly to the lifecycle of a single Azure resource (e.g., VM), allowing it to authenticate to Azure AD.

  • Lifecycle is bound to the Azure resource.
  • Azure automatically handles credential rotation.
  • Cannot be shared with other resources.
  • Simplifies secure access to other Azure services like Azure SQL, Key Vault, Storage.

Memory trick: System-assigned MI: VM's own ID, no secrets to hide!

More Implement and manage workload identities questions