Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
A global FinTech company uses Azure Kubernetes Service (AKS) clusters across multiple regions. Each AKS cluster needs to access an Azure Key Vault to retrieve sensitive secrets like database connection strings and API keys. The security team requires a solution that allows consistent access control across all clusters and simplifies credential management, avoiding the need to manually distribute and rotate secrets to each cluster. Which type of workload identity should you recommend?
- AAzure AD application registration with client secrets.
- BSystem-assigned managed identity for each AKS cluster.
- CUser-assigned managed identity.
- DService principal with a certificate.
Show answer & explanationAnswer & explanation
Correct answer: C. User-assigned managed identity.
User-assigned managed identities are standalone Azure resources that can be assigned to multiple Azure resources, including AKS clusters. This allows for centralized management and consistent access control across all clusters accessing the same Key Vault.
Why the other options are wrong
- A. Client secrets require manual management and rotation, which the security team wants to avoid.
- B. System-assigned managed identities are tied to a single resource and cannot be shared, making it inefficient for multiple AKS clusters needing the same permissions.
- D. Service principals with certificates still involve managing certificate lifecycle and distribution, which is more complex than managed identities.
User-assigned Managed Identity
An Azure AD identity created as a standalone Azure resource, distinct from any specific service instance, that can be assigned to multiple Azure resources to provide them with an identity for authentication.
- Created as a separate Azure resource.
- Can be assigned to multiple Azure resources.
- Lifecycle is independent of the resources it's assigned to.
Memory trick: User-assigned MI: One identity for many, shared access, no hassle, plenty.