Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy

A software development company is building a new microservices-based application on Azure. Each microservice is deployed as an Azure Function or Azure Container Instance. These microservices need to securely access other Azure services like Azure Key Vault and Azure Cosmos DB without using hardcoded credentials or secrets in their code. The security architect needs a solution that provides an automatically managed identity for each microservice, authenticated by Azure AD, to access other resources. Which Azure service or feature should be implemented?

  1. AService Principals
  2. BAzure AD Application Registrations
  3. CAzure Managed Identities
  4. DAzure AD Conditional Access
Show answer & explanation

Correct answer: C. Azure Managed Identities

Azure Managed Identities provide an automatically managed identity in Azure Active Directory for Azure services. This allows services to authenticate to other services that support Azure AD authentication without the need for developers to manage credentials in their code, directly addressing the requirement for secure, credential-free access.

Why the other options are wrong

  • A. Service Principals are the identity of an application in a specific tenant, but they still typically require associated client secrets or certificates to authenticate.
  • B. Azure AD Application Registrations are used to define an application's identity in Azure AD, but they still require managing client secrets or certificates.
  • D. Azure AD Conditional Access enforces policies for user access based on conditions, not for providing identities to Azure services.

Azure Managed Identities

Azure Managed Identities provide an identity for Azure services in Azure Active Directory (Azure AD). This allows Azure services to authenticate to other services that support Azure AD authentication without developers having to manage credentials.

  • Eliminates the need for hardcoded credentials.
  • Automatically managed by Azure AD.
  • Supports system-assigned and user-assigned identities.
  • Enhances security posture by reducing credential exposure.

Memory trick: Managed Identities give your services their own 'ID badge' for Azure AD.

More Design security for applications and data questions