A company is developing a serverless application using Azure Functions. The application needs to securely access resources in a different Azure subscription within the same Azure AD tenant. You want to implement a solution that allows the Azure Function to authenticate to these cross-subscription resources without hardcoding credentials and with minimal configuration. Which approach should you use?
- AEnable a system-assigned managed identity on the Azure Function and grant it permissions in the target subscription.
- BCreate a new Azure AD application registration in the target subscription and assign it permissions.
- CCreate a user-assigned managed identity, assign it to the Azure Function, and grant it permissions in the target subscription.
- DGenerate a Shared Access Signature (SAS) token for each resource in the target subscription.
Show answer & explanationAnswer & explanation
Correct answer: C. Create a user-assigned managed identity, assign it to the Azure Function, and grant it permissions in the target subscription.
User-assigned managed identities can be created once and then assigned to resources across different subscriptions (as long as they are within the same Azure AD tenant). This allows the Azure Function to authenticate using the user-assigned identity, which can then be granted specific permissions in the target subscription, fulfilling the requirements for secure, credential-free, and cross-subscription access.
Why the other options are wrong
- A. System-assigned managed identities are scoped to the resource they are enabled on. While they can access resources in other subscriptions, a user-assigned managed identity is often preferred for cross-subscription access due to its standalone nature and reusability.
- B. Creating a new application registration requires managing client secrets or certificates, which the question aims to avoid. Also, it's not the most 'minimal configuration' for this scenario.
- D. SAS tokens are primarily for storage and are not a general-purpose authentication mechanism for Azure AD-protected resources, nor do they align with 'without hardcoding credentials' for complex scenarios.
Cross-Subscription Managed Identity
The ability of a Managed Identity (typically user-assigned) to be used by an Azure resource in one subscription to access resources in another subscription, provided both subscriptions are in the same Azure AD tenant.
- Facilitates secure access across subscription boundaries.
- User-assigned identities are well-suited for this scenario.
- Requires granting appropriate RBAC permissions in the target subscription.
- Simplifies multi-subscription resource access management.
Memory trick: User Unlocks Universal Access Under Unified Tenant.