Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A development team is building a new microservices application that will consist of multiple Azure Function Apps, Azure Logic Apps, and Azure Web Apps. All of these services need to access a shared set of resources, including an Azure Key Vault and an Azure Storage Account. The security team requires a consistent identity across all these services for simplified management and access control. Which type of identity should be implemented?

  1. AService Principal with a client secret
  2. BSystem-assigned Managed Identity
  3. CUser-assigned Managed Identity
  4. DApplication Registration
Show answer & explanation

Correct answer: C. User-assigned Managed Identity

A user-assigned managed identity is a standalone Azure resource that can be assigned to multiple Azure services. This allows different services to share the same identity, simplifying access management and providing a consistent identity across various components of an application.

Why the other options are wrong

  • A. Service principals with client secrets require manual secret rotation and management, which the scenario aims to avoid by emphasizing 'simplified management'.
  • B. System-assigned managed identities are tied to a single resource and cannot be shared across multiple services.
  • D. Application registrations require manual credential management (secrets or certificates) and do not offer the 'managed' aspect of eliminating credential handling.

User-assigned Managed Identity

A standalone Azure resource that can be assigned to multiple Azure services, allowing them to share a common identity for simplified management and access control.

  • Independent Azure resource.
  • Can be assigned to multiple Azure resources.
  • Provides a consistent identity for distributed applications.

Memory trick: User's ID, shared wide, across the cloud, far and wide.

More Implement and manage workload identities questions