Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is implementing a new web application that needs to securely access Microsoft Graph API to retrieve user profiles. The application is hosted on an Azure App Service. The development team wants to avoid managing client secrets or certificates for authentication. The solution must ensure that the application's identity is automatically managed by Azure. Which type of identity should be assigned to the Azure App Service to meet these requirements?

  1. ASystem-assigned managed identity
  2. BService principal with client secret
  3. CApplication registration with certificate
  4. DUser-assigned managed identity
Show answer & explanation

Correct answer: A. System-assigned managed identity

A system-assigned managed identity is created directly on an Azure resource (like an App Service) and is tied to the lifecycle of that resource. It provides an automatically managed identity in Azure AD, eliminating the need to manage credentials.

Why the other options are wrong

  • B. A service principal with a client secret requires manual management of the secret and its rotation, which the question aims to avoid.
  • C. An application registration with a certificate also requires management of the certificate lifecycle, which the question aims to avoid.
  • D. User-assigned managed identities are standalone Azure resources that can be assigned to multiple Azure resources, offering more flexibility but still requiring a separate resource to be created and managed.

System-assigned Managed Identity

An identity created and managed by Azure AD that is directly tied to the lifecycle of a specific Azure resource, enabling that resource to authenticate to other Azure services without credential management.

  • Tied to the resource's lifecycle (deleted with the resource).
  • Automatically provisioned and managed by Azure.
  • Cannot be shared with other resources.

Memory trick: System-assigned: part of the system, User-assigned: you assign it.

More Implement an identity management solution questions