Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
A company has an Azure Function App that needs to access files in an Azure Storage Account. The security team wants to apply a granular access policy for the Function App, allowing it to only read blobs from a specific container within the Storage Account. They also want to avoid storing any credentials in the Function App code or configuration. How should you configure access for the Function App?
- AEnable anonymous public access for the specific container in the Azure Storage Account.
- BGenerate a Shared Access Signature (SAS) for the container and store it in the Function App settings.
- CCreate a system-assigned managed identity for the Function App and assign it the 'Storage Blob Data Reader' role scoped to the specific container.
- DCreate an Azure AD application registration, grant it 'Storage Blob Data Reader' permissions at the Storage Account level, and use its client secret.
Show answer & explanationAnswer & explanation
Correct answer: C. Create a system-assigned managed identity for the Function App and assign it the 'Storage Blob Data Reader' role scoped to the specific container.
A system-assigned managed identity provides a secure, credential-less way for the Function App to authenticate. By assigning the 'Storage Blob Data Reader' role, scoped to the specific container, it adheres to the principle of least privilege and prevents credential storage.
Why the other options are wrong
- A. Enabling anonymous public access is a severe security risk and grants unrestricted access to the container, violating security best practices.
- B. SAS tokens are credentials that still need to be managed and stored securely, which is less ideal than managed identities.
- D. Using an application registration with a client secret reintroduces credential management and does not leverage the benefits of managed identities for Azure resources.
Managed Identity with RBAC
Combining Azure Managed Identities for secure, credential-less authentication with Azure Role-Based Access Control (RBAC) to grant granular, least-privilege access to Azure resources.
- Managed Identity handles authentication to Azure AD.
- RBAC defines specific permissions and scope.
- Eliminates credential management and enforces least privilege.
Memory trick: Managed Identity + RBAC: Identity gets the key, RBAC tells it where to play.