Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy
A development team is building a new microservices application that will consist of multiple Azure Functions and Azure App Services. All these components need to access a shared Azure Key Vault to retrieve secrets. The team wants a single identity that can be assigned to all these different resources, simplifying management and role assignments. Which type of workload identity should you recommend?
- AAzure AD application registration with a certificate
- BUser-assigned managed identity
- CAzure AD application registration with a client secret
- DSystem-assigned managed identity
Show answer & explanationAnswer & explanation
Correct answer: B. User-assigned managed identity
User-assigned managed identities can be created once and then assigned to multiple Azure resources, such as Azure Functions and App Services. This centralizes identity management and allows for a single set of permissions to be applied across all connected resources.
Why the other options are wrong
- A. This also requires manual certificate management and deployment, which is more complex than a user-assigned managed identity.
- C. While an application registration can be used, it requires manual management of client secrets, which managed identities eliminate.
- D. System-assigned managed identities are tied to a single resource's lifecycle and cannot be shared across multiple resources.
User-Assigned Managed Identity
A standalone Azure resource that can be created, configured, and then assigned to multiple Azure services, enabling them to authenticate to Azure AD.
- Independent lifecycle from the Azure resources it's assigned to.
- Can be assigned to multiple Azure resources.
- Allows for centralized management of permissions for a group of resources.
- Eliminates the need for developers to manage credentials.
Memory trick: User-assigned identity, like a universal key for many locks.