Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
A development team is building a new microservices application that will consist of multiple Azure Function Apps, Azure Logic Apps, and Azure Web Apps. All of these services need to access a shared set of resources, including an Azure Key Vault and an Azure Storage Account. The security team requires a consistent identity across all these services for simplified management and access control. Which type of identity should be implemented?
- AService Principal with a client secret
- BSystem-assigned Managed Identity
- CUser-assigned Managed Identity
- DApplication Registration
Show answer & explanationAnswer & explanation
Correct answer: C. User-assigned Managed Identity
A user-assigned managed identity is a standalone Azure resource that can be assigned to multiple Azure services. This allows different services to share the same identity, simplifying access management and providing a consistent identity across various components of an application.
Why the other options are wrong
- A. Service principals with client secrets require manual secret rotation and management, which the scenario aims to avoid by emphasizing 'simplified management'.
- B. System-assigned managed identities are tied to a single resource and cannot be shared across multiple services.
- D. Application registrations require manual credential management (secrets or certificates) and do not offer the 'managed' aspect of eliminating credential handling.
User-assigned Managed Identity
A standalone Azure resource that can be assigned to multiple Azure services, allowing them to share a common identity for simplified management and access control.
- Independent Azure resource.
- Can be assigned to multiple Azure resources.
- Provides a consistent identity for distributed applications.
Memory trick: User's ID, shared wide, across the cloud, far and wide.