Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard
A company is using Azure AD and wants to standardize their approach to giving applications permissions to access other Azure AD-protected resources (e.g., Microsoft Graph API, custom APIs). They need to ensure that these application permissions are centrally managed, auditable, and adhere to the principle of least privilege. Which type of identity should be used to represent these applications in Azure AD and manage their permissions?
- AUser identity
- BManaged identity
- CService principal
- DGuest user
Show answer & explanationAnswer & explanation
Correct answer: C. Service principal
A service principal is an identity created in Azure AD that represents an application or service that needs to access resources. It defines what the application can actually do in the specific tenant, allowing for centralized management, auditable permissions, and adherence to the principle of least privilege by assigning specific roles or API permissions.
Why the other options are wrong
- A. User identities are for human users, not applications.
- B. Managed identities are for Azure resources (like VMs, Functions) to authenticate to other Azure services without managing secrets; they are a *type* of service principal but the broader term 'service principal' encompasses all applications.
- D. Guest users are external human users invited to the tenant, not for applications.
Azure AD Service Principal
A security identity that represents an application, service, or automation tool that needs to access specific Azure resources.
- Acts as the instance of an application object in a specific tenant.
- Used to assign permissions to applications, following least privilege.
- Can be client secret or certificate-based for authentication.
Memory trick: Service Principal: The app's ID card for accessing resources.