Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureHard

A software development company uses Azure DevOps to manage its CI/CD pipelines. They need to ensure that all build agents, whether hosted or self-hosted, can securely retrieve credentials and configuration settings from Azure Key Vault without exposing these secrets in plaintext during the build process. The solution must adhere to the principle of least privilege and avoid hardcoding credentials. Which authentication method should be configured for the build agents?

  1. ACertificate-based authentication with certificates stored on the build agent
  2. BManaged identities for Azure resources
  3. CAzure Active Directory user accounts with multifactor authentication
  4. DService principal with a client secret stored in the build pipeline variables
Show answer & explanation

Correct answer: B. Managed identities for Azure resources

Managed identities for Azure resources (specifically system-assigned or user-assigned managed identities) provide an identity for Azure resources like VMs or Azure DevOps agents. This allows them to authenticate to Key Vault without having to manage credentials, aligning with least privilege and avoiding hardcoding.

Why the other options are wrong

  • A. Certificate-based authentication requires certificate management and distribution, which is more complex and less integrated than managed identities for Azure resources.
  • C. User accounts are not ideal for automated processes and require human intervention for MFA, which is unsuitable for CI/CD pipelines.
  • D. Storing client secrets in pipeline variables, even if marked secret, still involves managing a secret and is less secure than managed identities.

Managed Identities for Azure Resources

Managed identities for Azure resources provide an automatically managed identity in Azure Active Directory for Azure services. This identity can be used to authenticate to any service that supports Azure AD authentication without managing credentials.

  • Automatically managed in Azure AD.
  • Eliminates the need for developers to manage credentials.
  • Supports system-assigned and user-assigned identities.
  • Enhances security by adhering to the principle of least privilege.

Memory trick: Managed Identity for Machines, Service Principals for Apps, Users for Humans.

More Design security for infrastructure questions