Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

A software development company uses Azure DevOps to manage its CI/CD pipelines. They need to ensure that the pipelines can securely access Azure Key Vault to retrieve secrets for application deployments without embedding credentials directly in the pipeline definitions or scripts. The solution must adhere to the principle of least privilege and be easy to manage across multiple projects. Which Azure identity feature should be implemented?

  1. APersonal Access Tokens (PATs) for Azure DevOps
  2. BService Principals with client secrets
  3. CKey Vault access policies with IP whitelisting
  4. DManaged Identities for Azure Resources
Show answer & explanation

Correct answer: D. Managed Identities for Azure Resources

Managed Identities for Azure Resources provide an automatically managed identity in Azure Active Directory for Azure services. By assigning a system-assigned or user-assigned managed identity to the Azure DevOps agent or directly to the pipeline, it can authenticate to Azure Key Vault without requiring secrets or certificates to be managed by developers, aligning with least privilege and ease of management.

Why the other options are wrong

  • A. PATs are for user-based authentication to Azure DevOps itself, not for Azure DevOps agents to access Azure Key Vault.
  • B. Service Principals still require managing client secrets or certificates, which the requirement seeks to avoid.
  • C. Key Vault access policies with IP whitelisting are a network control, not an identity solution, and don't solve the credential management issue.

Managed Identities for Azure Resources

An Azure Active Directory feature that provides Azure services with an automatically managed identity, eliminating the need for developers to manage credentials.

  • Simplifies secret management for cloud applications.
  • Automatically handled by Azure, enhancing security.
  • Supports system-assigned and user-assigned identities.

Memory trick: Managed Identities are like a 'robot ID card' that Azure handles.

More Design security for infrastructure questions