Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard

A global manufacturing company has multiple Azure subscriptions, each managed by a different regional team. A central logging service, hosted in Subscription A, needs to collect logs from Azure resources across all other subscriptions (Subscription B, C, D, etc.). All regional teams want to maintain control over their subscriptions but need to grant the central logging service access. Which approach should be used to enable the central logging service to access resources in other subscriptions?

  1. ACreate a service principal in each subscription (B, C, D) and grant it Reader access to Subscription A.
  2. BUse a system-assigned managed identity for the central logging service and manually assign Reader role in each target subscription.
  3. CCreate a user-assigned managed identity in Subscription A, and have each regional team (Subscription B, C, D) assign Reader role to this identity on their respective subscriptions.
  4. DConfigure a multi-tenant application registration for the central logging service and grant it Reader access in each subscription.
Show answer & explanation

Correct answer: C. Create a user-assigned managed identity in Subscription A, and have each regional team (Subscription B, C, D) assign Reader role to this identity on their respective subscriptions.

A user-assigned managed identity provides a single, centrally managed identity that can be created in one subscription (Subscription A) and then assigned permissions (like Reader role) across multiple other subscriptions (B, C, D). This allows each regional team to independently grant the necessary access to the centralized service without creating separate identities or managing shared secrets.

Why the other options are wrong

  • A. This approach is backward; the logging service needs access to B, C, D, not the other way around. Also, creating multiple service principals is less manageable than a single managed identity.
  • B. A system-assigned managed identity is tied to a single resource and cannot be directly 'assigned' to other subscriptions in this manner. It gets permissions in the subscription it resides in or others via RBAC, but a user-assigned identity is better for cross-subscription sharing.
  • D. Multi-tenant application registrations are for applications used by different Azure AD tenants, not for accessing resources across different subscriptions within the same tenant. Managed identities are preferred for Azure resource authentication.

Cross-Subscription Managed Identity

Using a user-assigned managed identity to grant an Azure resource (e.g., a service) access to resources located in different Azure subscriptions within the same Azure AD tenant.

  • Requires a user-assigned managed identity, as it's a standalone resource.
  • The managed identity is created in one subscription and assigned RBAC roles in others.
  • Simplifies centralized service access to distributed resources.
  • Allows decentralized control over permissions by subscription owners.

Memory trick: User-assigned identity: One key to unlock many subscription doors.

More Implement and manage workload identities questions