Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy
A development team is building a new application that will run on an Azure Virtual Machine and needs to securely access Azure Key Vault to retrieve secrets. The team wants to avoid hardcoding credentials or managing service principal secrets. Which identity solution should they implement for the Azure Virtual Machine?
- AUser-assigned identity
- BManaged Identity
- CService Principal with a client secret
- DAzure AD Application Proxy
Show answer & explanationAnswer & explanation
Correct answer: B. Managed Identity
Managed Identities provide an automatically managed identity in Azure AD for Azure resources. They eliminate the need for developers to manage credentials, as Azure handles the lifecycle of the identity and its authentication to Azure services.
Why the other options are wrong
- A. User-assigned identity is a type of Managed Identity, but 'Managed Identity' is the broader, more direct answer to the problem statement of avoiding credential management. Both system-assigned and user-assigned solve this problem.
- C. Service Principals with client secrets require manual secret management and rotation, which the team wants to avoid.
- D. Azure AD Application Proxy provides secure remote access to on-premises web apps, not identity for Azure VMs to access other Azure services.
Azure Managed Identities
Automatically managed identities in Azure Active Directory that Azure services can use to authenticate to cloud services without managing credentials.
- Eliminates hardcoding credentials.
- Two types: system-assigned and user-assigned.
- Azure manages the identity lifecycle and secret rotation.
Memory trick: Managed Identity is like having a trusted valet for your Azure resources' credentials.