Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is implementing a new application that will be hosted in Azure. This application needs to securely access data stored in Azure Key Vault. The developers want to avoid embedding credentials in the application code and ensure that the application's identity is managed directly by Azure. Which type of identity should be used for the application?

  1. AAzure AD service principal
  2. BSystem-assigned managed identity
  3. CAzure AD user account
  4. DUser-assigned managed identity
Show answer & explanation

Correct answer: B. System-assigned managed identity

A system-assigned managed identity is created and managed automatically by Azure for a specific Azure resource. It's ideal for scenarios where a single application needs to authenticate to other Azure services without managing credentials manually.

Why the other options are wrong

  • A. A service principal is the identity of an application in Azure AD, but managed identities simplify its use by automatically handling credential management.
  • C. An Azure AD user account is for human interaction, not for applications to authenticate to services.
  • D. User-assigned managed identities are created independently and can be assigned to multiple resources, which is more flexible but not strictly necessary if only one application needs an identity.

System-assigned Managed Identity

An identity created and managed by Azure for a specific Azure resource, allowing it to authenticate to other Azure services securely.

  • Tied to the lifecycle of the resource; deleted when the resource is deleted.
  • Automatically handles credential rotation.
  • Removes the need for developers to manage credentials in code.

Memory trick: App identity: System-assigned, User-assigned, or Service Principal's call.

More Implement an identity management solution questions