Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A company is implementing a new line-of-business application that will be hosted in Azure. This application needs to access data stored in an Azure Storage Account. To enhance security, the company wants to avoid storing credentials within the application's code or configuration files. This solution should also allow for automated credential rotation and simplified management. Which Azure AD feature should be implemented to securely manage the application's access to the storage account?

  1. AAzure AD Connect
  2. BAzure AD B2C
  3. CAzure AD Managed Identities
  4. DAzure AD Application Proxy
Show answer & explanation

Correct answer: C. Azure AD Managed Identities

Azure AD Managed Identities provide an automatically managed identity for Azure services, eliminating the need for developers to manage credentials. This identity can then be used to authenticate to services like Azure Storage.

Why the other options are wrong

  • A. Azure AD Connect synchronizes on-premises AD with Azure AD, which is irrelevant for Azure service-to-service authentication.
  • B. Azure AD B2C is for customer-facing applications, not internal Azure service-to-service authentication.
  • D. Azure AD Application Proxy provides secure remote access to on-premises web applications, not for Azure internal service authentication.

Azure AD Managed Identities

A feature of Azure Active Directory that provides Azure services with an automatically managed identity in Azure AD.

  • Eliminates the need for developers to manage credentials during service-to-service authentication.
  • Supports two types: System-assigned and User-assigned.
  • Can be granted permissions to access other Azure resources via Azure RBAC.

Memory trick: Machines talking securely without secrets.

More Manage identity and access questions