Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy
A software development company is building a new microservices-based application on Azure. The application uses Azure Functions, Azure Storage, and Azure Key Vault. The developers want to avoid embedding credentials in their code or configuration files for accessing Azure Storage and Key Vault. Which identity solution should they implement?
- AManaged Identities for Azure Resources
- BService Principals
- CAzure Active Directory B2C
- DAzure AD Application Proxies
Show answer & explanationAnswer & explanation
Correct answer: A. Managed Identities for Azure Resources
Managed Identities for Azure Resources (formerly Managed Service Identity) provides Azure services with an automatically managed identity in Azure Active Directory. This allows services like Azure Functions to authenticate to other Azure services (like Storage and Key Vault) without developers having to manage credentials in code.
Why the other options are wrong
- B. Service Principals are used for non-human entities but require manual credential management (client secrets or certificates) for authentication.
- C. Azure Active Directory B2C is for customer-facing identity management, not for Azure service authentication.
- D. Azure AD Application Proxies provide secure remote access to on-premises web applications, which is unrelated to this scenario.
Managed Identities for Azure Resources
An Azure Active Directory feature that provides Azure services with an automatically managed identity in Azure AD, allowing them to authenticate to other Azure services without requiring developers to manage credentials.
- Eliminates the need for credential management in code.
- Identities are automatically managed by Azure.
- Supports both system-assigned and user-assigned identities.
- Uses OAuth 2.0 and Azure AD for authentication.
Memory trick: Managed Identity: Azure handles the key, not your code.