Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A client is developing a new serverless application in Azure that uses Azure Functions and needs to access data stored in Azure Storage Accounts. The security team wants to eliminate the use of connection strings and hardcoded credentials in the application code. They need a solution that allows the Azure Function to securely authenticate to the Azure Storage Account without managing any secrets. Which Azure AD feature should the client implement?

  1. AAzure AD Application Proxy
  2. BAzure AD Identity Protection
  3. CAzure AD Managed Identities
  4. DAzure AD B2B collaboration
Show answer & explanation

Correct answer: C. Azure AD Managed Identities

Azure AD Managed Identities provide an Azure AD identity for Azure resources, allowing them to authenticate to services that support Azure AD authentication without storing credentials in code. This is the ideal solution for Azure Functions accessing Azure Storage Accounts securely and without secrets.

Why the other options are wrong

  • A. Azure AD Application Proxy provides secure remote access to on-premises web applications.
  • B. Azure AD Identity Protection detects and remediates identity-based risks, not for service-to-service authentication.
  • D. Azure AD B2B collaboration is for inviting external users (guests) to access your Azure AD resources.

Azure AD Managed Identities

Automatically managed identities in Azure AD for Azure resources, eliminating the need for developers to manage credentials.

  • Simplifies authentication for Azure services.
  • Supports system-assigned and user-assigned managed identities.
  • Enhances security by removing secrets from code.

Memory trick: Managed identity, no secrets, just smooth access for services.

More Manage identity and access questions