Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy
A company is developing a new serverless application using Azure Functions. This application needs to securely access data stored in an Azure SQL Database. The security team mandates that no secrets or connection strings should be hardcoded or stored in application settings. The solution must ensure that the function app can authenticate to the SQL Database without manual credential management. Which type of identity should be used?
- AUser-assigned Managed Identity
- BService Principal
- CSystem-assigned Managed Identity
- DApplication Registration
Show answer & explanationAnswer & explanation
Correct answer: C. System-assigned Managed Identity
A system-assigned managed identity is automatically created and managed by Azure for a specific Azure resource, such as an Azure Function App. This allows the resource to authenticate to other Azure services that support Azure AD authentication without managing credentials.
Why the other options are wrong
- A. User-assigned managed identities are standalone Azure resources that can be assigned to multiple Azure resources, but for a single function app needing direct access, system-assigned is simpler.
- B. Service Principals are identities created when an application registration is made, but they still require credential management (e.g., client secrets or certificates).
- D. Application Registrations are for applications that need to authenticate to Azure AD but are not directly tied to a specific Azure resource and require manual credential management.
System-assigned Managed Identity
An identity automatically created and managed by Azure for a specific Azure resource, allowing it to authenticate to other Azure services without credential management.
- Automatically created and deleted with the resource.
- Tied to the lifecycle of a single Azure resource.
- Eliminates the need for developers to manage credentials.
Memory trick: System's single, User's shared, App's a separate key.