Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company is onboarding a new application that will be hosted as an Azure App Service. This application needs to securely access Azure Key Vault to retrieve secrets (e.g., database connection strings) without requiring any hardcoded credentials in its configuration or code. The application itself will be the identity accessing Key Vault. Which type of managed identity should be configured for the Azure App Service?
- AAzure AD application registration
- BService principal
- CUser-assigned managed identity
- DSystem-assigned managed identity
Show answer & explanationAnswer & explanation
Correct answer: D. System-assigned managed identity
A system-assigned managed identity is directly tied to the lifecycle of an Azure resource (like an App Service). It is automatically created, managed, and deleted with the resource, and it allows the resource to authenticate to other Azure services (like Key Vault) without managing credentials.
Why the other options are wrong
- A. Azure AD application registration is the manual process of creating an identity for an application; managed identities automate this for Azure resources.
- B. A service principal is the representation of an application identity in Azure AD, but managed identities are a more secure and automated way to handle service principals for Azure resources.
- C. User-assigned managed identities are standalone resources that can be assigned to multiple Azure resources, offering more flexibility but not strictly necessary for a single application's identity.
System-assigned Managed Identity
An Azure AD identity automatically created and tied to the lifecycle of a single Azure resource, allowing it to authenticate to other Azure services.
- Automatically created and deleted with the Azure resource.
- Cannot be shared across multiple resources.
- Simplifies credential management for Azure services.
Memory trick: System-assigned is 'Stuck with the System', User-assigned is 'Used by Anyone'.