Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy

A company is developing a new serverless application using Azure Functions. This application needs to access data stored in an Azure SQL Database. The security team has mandated that no connection strings or secrets should be stored directly in the Function App configuration or code. You need to recommend the most secure and efficient way for the Azure Function to authenticate to Azure SQL Database.

  1. AUse an Azure Storage Account to store the SQL connection string and retrieve it at runtime.
  2. BConfigure a system-assigned managed identity for the Azure Function and grant it appropriate permissions to the Azure SQL Database.
  3. CCreate an Azure Active Directory (Azure AD) application registration, generate a client secret, and use it for authentication.
  4. DImplement a custom authentication provider within the Azure Function to handle SQL authentication.
Show answer & explanation

Correct answer: B. Configure a system-assigned managed identity for the Azure Function and grant it appropriate permissions to the Azure SQL Database.

Managed identities for Azure resources provide an Azure AD-managed identity for Azure services, eliminating the need for developers to manage credentials. A system-assigned managed identity is tied to the lifecycle of the Azure resource and is ideal for this scenario.

Why the other options are wrong

  • A. Storing connection strings in Azure Storage still involves managing a secret (the storage account key or SAS token) and is less secure than managed identities.
  • C. Using an Azure AD application registration with a client secret reintroduces the problem of managing and rotating secrets, which the security team wants to avoid.
  • D. Implementing a custom authentication provider is overly complex and does not natively solve the problem of secure credential management for Azure SQL Database access.

System-assigned Managed Identity

An Azure AD identity automatically created and managed by Azure, tied to the lifecycle of a specific Azure resource, allowing that resource to authenticate to other Azure services without needing credentials.

  • Automatically created and deleted with the Azure resource.
  • Cannot be shared with other resources.
  • Ideal for single-resource authentication needs.

Memory trick: Managed Identity: Azure's key, no secret needed, just trust and be free.

More Implement and manage workload identities questions