Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company is migrating several of its applications to Azure. One critical legacy application is hosted on an Azure Virtual Machine (VM) and requires access to secrets stored in an Azure Key Vault. The security team insists that the application should not store any credentials or secrets directly in its code or configuration files. Which Azure AD feature should be used to grant the VM secure access to the Key Vault?
- AApplication Registrations
- BConditional Access Policies
- CManaged Identities
- DService Principals
Show answer & explanationAnswer & explanation
Correct answer: C. Managed Identities
Managed Identities for Azure resources provide an automatically managed identity in Azure AD for Azure services, such as VMs. This allows the VM to authenticate to services like Key Vault without requiring developers to manage credentials in code.
Why the other options are wrong
- A. Application Registrations define an application's identity in Azure AD but still require a service principal and associated credentials for authentication.
- B. Conditional Access Policies control access based on conditions but do not provide an identity for an application to authenticate to resources.
- D. Service Principals are identities used by applications or services to access resources, but they typically require manual credential management (client secrets or certificates).
Managed Identities for Azure Resources
An Azure AD feature that provides an automatically managed identity for Azure services, allowing them to authenticate to other Azure AD-protected services without developers needing to manage credentials.
- Eliminates credential management for developers.
- Two types: System-assigned and User-assigned.
- Used for secure access to Azure Key Vault, Storage, etc.
Memory trick: Identity managed, secrets vanished, access granted.