Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A development team is building a new microservices application that will consist of multiple Azure Functions. Each Azure Function needs to access a specific Azure Storage account and an Azure Cosmos DB database. To ensure granular access control and simplify management, each Azure Function should have its own distinct identity. Which type of Managed Identity should you recommend?

  1. AMultiple system-assigned managed identities, one for each Azure Function.
  2. BA single user-assigned managed identity, shared by all Azure Functions.
  3. CA single system-assigned managed identity for the entire Function App.
  4. DMultiple user-assigned managed identities, one for each Azure Function.
Show answer & explanation

Correct answer: D. Multiple user-assigned managed identities, one for each Azure Function.

User-assigned managed identities are separate Azure resources that can be assigned to multiple Azure resources. By creating a distinct user-assigned managed identity for each Azure Function, you achieve granular access control and ensure each function has its own identity, which can then be granted specific permissions to Storage and Cosmos DB.

Why the other options are wrong

  • A. Azure Functions within a Function App cannot each have their own system-assigned managed identity; the system-assigned identity is at the Function App level.
  • B. A single user-assigned managed identity shared by all functions would not provide the required granular access control for each distinct function.
  • C. A system-assigned identity for the entire Function App would mean all functions share the same identity, making granular access control for individual functions difficult.

User-assigned Managed Identity

A type of Managed Identity that is created as a standalone Azure resource, allowing it to be assigned to multiple Azure resources and providing flexibility for shared or granular identities.

  • Lifecycle independent of associated resources.
  • Can be assigned to multiple resources.
  • Useful for shared identities or granular control across components.
  • Requires explicit creation and assignment.

Memory trick: Users Unite Unique Units.

More Implement and manage workload identities questions