Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy

A financial institution is developing a highly sensitive internal application that will process confidential customer data. This application runs on an Azure Virtual Machine. The security policy mandates that the application must use a unique, non-sharable identity for authentication to Azure Key Vault to retrieve secrets, and this identity must be automatically removed when the VM is deleted. Which type of managed identity should be configured for this application?

  1. AAzure AD application registration.
  2. BUser-assigned managed identity.
  3. CService principal with a client secret.
  4. DSystem-assigned managed identity.
Show answer & explanation

Correct answer: D. System-assigned managed identity.

A system-assigned managed identity is tied directly to the lifecycle of the Azure resource (the VM in this case), is unique to that resource, and is automatically deleted when the resource is deleted. This perfectly matches the requirements for a non-sharable, automatically managed identity.

Why the other options are wrong

  • A. An Azure AD application registration would require manual secret management and is not automatically tied to the VM's lifecycle.
  • B. User-assigned managed identities are standalone resources that can be shared and have an independent lifecycle, not meeting the non-sharable and auto-delete requirements.
  • C. Service principals with client secrets involve manual secret management and rotation, which is less secure and efficient than managed identities.

System-assigned Managed Identity (Scenario based)

An Azure AD identity automatically created and managed by Azure, tied to the lifecycle of a specific Azure resource, providing unique, non-sharable authentication capabilities to other Azure services.

  • Unique to a single Azure resource.
  • Lifecycle is bound to the parent resource.
  • No manual credential management required.

Memory trick: System-assigned: VM's own shadow, bound to its life, no sharing allowed.

More Implement and manage workload identities questions