Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A global manufacturing company has multiple Azure subscriptions, each managed by a different department. A central automation script, running on an Azure Automation Account in Subscription A, needs to access and update resources (e.g., start/stop VMs) in Subscription B and Subscription C. The security team insists on using managed identities for authentication and wants to simplify the management of this identity across subscriptions. How should the identity for the automation account be configured?

  1. AEnable a System-assigned Managed Identity on the Automation Account and grant it permissions in all subscriptions.
  2. BEnable a System-assigned Managed Identity on the Automation Account and then create a federated credential for it in Subscription B and C.
  3. CCreate a User-assigned Managed Identity in Subscription A, assign it to the Automation Account, and grant it permissions in Subscription B and C.
  4. DCreate an Application Registration in Azure AD and use its client secret in the Automation Account.
Show answer & explanation

Correct answer: C. Create a User-assigned Managed Identity in Subscription A, assign it to the Automation Account, and grant it permissions in Subscription B and C.

A user-assigned managed identity is an independent Azure resource that can be created in one subscription and then assigned to resources (like an Automation Account) in the same or different subscriptions. This allows for centralized management of the identity while granting it access across multiple subscriptions.

Why the other options are wrong

  • A. While a system-assigned MI can be granted permissions across subscriptions, it's tied to the Automation Account's lifecycle. A user-assigned MI offers more flexibility for sharing and independent lifecycle management.
  • B. Federated credentials are for external workloads, not for an Azure resource authenticating to other Azure resources within the same tenant, even across subscriptions.
  • D. Application registrations require manual credential management (client secrets), which managed identities aim to avoid.

Cross-Subscription Managed Identity

Leveraging User-assigned Managed Identities to provide a single, consistent identity for Azure resources that need to access other resources across different Azure subscriptions.

  • Uses User-assigned Managed Identities.
  • Simplifies access management across subscription boundaries.
  • Identity can be managed independently of the consuming resource.

Memory trick: User's ID, across the lines, subscriptions connected, it combines.

More Implement and manage workload identities questions