Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
A development team is building a new microservices application composed of several Azure Functions and Azure App Services. All these services need to access a shared Azure Key Vault to retrieve application secrets. The team wants a solution that allows them to manage a single identity for all these services, simplifying permissions management and ensuring consistent access control. Which type of managed identity should they use?
- AAzure AD application registration with a client secret.
- BService principal with a certificate.
- CUser-assigned managed identity.
- DSystem-assigned managed identity for each service.
Show answer & explanationAnswer & explanation
Correct answer: C. User-assigned managed identity.
A user-assigned managed identity can be created once and then assigned to multiple Azure resources (like multiple Function Apps and App Services). This allows for centralized management of permissions and a consistent identity across all services accessing the shared Key Vault.
Why the other options are wrong
- A. Client secrets require manual management and rotation, which is less secure and efficient than managed identities.
- B. Service principals with certificates still involve certificate lifecycle management and distribution, which is more complex than managed identities.
- D. System-assigned identities are unique to each resource and cannot be shared, leading to multiple identities to manage for the shared Key Vault access.
User-assigned MI for Shared Access
An Azure AD identity created as a standalone resource, ideal for scenarios where multiple Azure resources need to share the same identity to access a common resource, simplifying permission management.
- Independent lifecycle from assigned resources.
- Can be assigned to multiple Azure services.
- Centralizes permissions management for shared resources.
Memory trick: User-assigned MI: One identity for many friends, shared key vault, security transcends.