Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A development team is building a new microservices application composed of several Azure Functions and Azure App Services. All these services need to access a shared Azure Key Vault to retrieve application secrets. The team wants a solution that allows them to manage a single identity for all these services, simplifying permissions management and ensuring consistent access control. Which type of managed identity should they use?

  1. AAzure AD application registration with a client secret.
  2. BService principal with a certificate.
  3. CUser-assigned managed identity.
  4. DSystem-assigned managed identity for each service.
Show answer & explanation

Correct answer: C. User-assigned managed identity.

A user-assigned managed identity can be created once and then assigned to multiple Azure resources (like multiple Function Apps and App Services). This allows for centralized management of permissions and a consistent identity across all services accessing the shared Key Vault.

Why the other options are wrong

  • A. Client secrets require manual management and rotation, which is less secure and efficient than managed identities.
  • B. Service principals with certificates still involve certificate lifecycle management and distribution, which is more complex than managed identities.
  • D. System-assigned identities are unique to each resource and cannot be shared, leading to multiple identities to manage for the shared Key Vault access.

User-assigned MI for Shared Access

An Azure AD identity created as a standalone resource, ideal for scenarios where multiple Azure resources need to share the same identity to access a common resource, simplifying permission management.

  • Independent lifecycle from assigned resources.
  • Can be assigned to multiple Azure services.
  • Centralizes permissions management for shared resources.

Memory trick: User-assigned MI: One identity for many friends, shared key vault, security transcends.

More Implement and manage workload identities questions