Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy
A software development company is building a new microservices-based application on Azure. Each microservice needs to securely access other Azure resources, such as Azure Key Vault for secrets and Azure Storage for data. These microservices are deployed as Azure App Services. The security architect wants to eliminate the need for developers to manage credentials or connection strings in code for these interactions. Which security mechanism should be implemented?
- AShared Access Signatures (SAS)
- BService Principals
- CManaged Identities for Azure Resources
- DAzure Active Directory (Azure AD) application registrations
Show answer & explanationAnswer & explanation
Correct answer: C. Managed Identities for Azure Resources
Managed Identities for Azure Resources provides an Azure AD identity for Azure services, eliminating the need for developers to manage credentials. The identity is managed by Azure, simplifying secure access to other Azure AD-protected resources.
Why the other options are wrong
- A. SAS tokens provide delegated access to storage but require management and are not a general solution for all Azure resources.
- B. Service Principals are the underlying identity for application registrations but still require credential management (client secrets/certificates) if not used via Managed Identities.
- D. Azure AD application registrations are used for applications outside of Azure services or for more complex scenarios, requiring credential management.
Managed Identities for Azure Resources
An Azure Active Directory feature that provides an automatically managed identity for Azure services, allowing them to authenticate to other Azure AD-protected services without developers needing to manage credentials.
- Automatic Azure AD identity for Azure services.
- Eliminates credential management in code.
- Simplifies secure access to other Azure AD-protected resources.
- Two types: System-assigned and User-assigned.
Memory trick: Managed Identities are like VIP passes for your services, no need for a wallet.