Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A company is migrating its legacy applications to Azure. One critical application, currently running on an on-premises server, uses a service account with a password for authentication to an LDAP directory. When migrating this application to an Azure Virtual Machine, the security team insists on eliminating hardcoded passwords and secrets. Additionally, the application needs to interact with other Azure services like Azure SQL Database and Azure Key Vault. Which Azure AD feature provides the most secure and manageable solution for this application's authentication needs?

  1. AConfigure a system-assigned managed identity for the Azure Virtual Machine.
  2. BMigrate the LDAP directory to Azure AD DS and use traditional username/password authentication.
  3. CStore all credentials in Azure Key Vault and retrieve them using a custom credential provider.
  4. DCreate a service principal with a client secret for the application.
Show answer & explanation

Correct answer: A. Configure a system-assigned managed identity for the Azure Virtual Machine.

A system-assigned managed identity for the Azure Virtual Machine allows the VM, and thus the application running on it, to authenticate to Azure AD-protected services (like Azure SQL and Key Vault) without managing any credentials. This eliminates hardcoded passwords and is highly secure.

Why the other options are wrong

  • B. While migrating to Azure AD DS for LDAP is good, it doesn't solve the problem of the application itself authenticating to other Azure services without credentials.
  • C. Storing credentials in Key Vault still requires the application to authenticate to Key Vault itself, which then leads back to the need for a managed identity or a secret to access Key Vault initially.
  • D. Using a service principal with a client secret reintroduces the problem of managing and rotating secrets, which the security team wants to avoid.

Managed Identity for Azure VM

An Azure AD identity assigned to an Azure Virtual Machine, allowing the VM and applications running on it to authenticate to other Azure services securely without managing credentials.

  • Eliminates hardcoded credentials.
  • Supports both system-assigned and user-assigned types.
  • Seamless integration with Azure AD-protected services.

Memory trick: VM's MI: The machine gets its own ID, no secrets for apps to hide.

More Implement and manage workload identities questions