Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A large enterprise is migrating several critical line-of-business applications to Azure. These applications historically relied on service accounts with embedded credentials for accessing other services and databases. The security team wants to eliminate hardcoded credentials and implement a more secure, automated authentication method for these applications when running on Azure Virtual Machines. Which Azure AD feature should be recommended?
- AAzure AD Conditional Access
- BManaged Identities for Azure Resources
- CAzure AD Application Proxy
- DService Principals with client secrets
Show answer & explanationAnswer & explanation
Correct answer: B. Managed Identities for Azure Resources
Managed Identities for Azure Resources provide an automatically managed identity for Azure services to authenticate to cloud services without credentials in code. This directly addresses the need to eliminate hardcoded credentials for applications running on Azure VMs.
Why the other options are wrong
- A. Azure AD Conditional Access controls access based on conditions but does not provide an identity for applications to authenticate with.
- C. Azure AD Application Proxy provides secure remote access to on-premises web applications, not for eliminating embedded credentials for Azure-hosted apps.
- D. Service Principals with client secrets still involve managing a secret, which the requirement aims to eliminate. Managed Identities remove the need for manual secret management.
Managed Identities for Azure Resources
Managed Identities provide an identity for Azure services to use when connecting to resources that support Azure AD authentication. This eliminates the need for developers to manage credentials by allowing Azure to manage the lifecycle of the identity.
- Automatically managed by Azure.
- Removes the need for developers to manage credentials.
- Can be assigned to Azure resources like VMs, App Services, Functions.
- Supports system-assigned and user-assigned types.
Memory trick: Managed Identities: No Keys to Lose, No Credentials to Abuse.