Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A software development company uses Azure App Service to host several RESTful APIs. These APIs need to securely access data from an Azure SQL Database. The security team mandates that the APIs should not store any credentials directly and should use a managed identity for authentication to the SQL Database. Which type of managed identity should be configured for the App Service?
- ASystem-assigned managed identity.
- BService principal with client secret.
- CUser-assigned managed identity.
- DApplication Gateway identity.
Show answer & explanationAnswer & explanation
Correct answer: A. System-assigned managed identity.
A system-assigned managed identity is created directly for the Azure App Service instance. It is automatically managed by Azure, tied to the lifecycle of the App Service, and its credentials are automatically rotated. This meets the requirements of not storing credentials directly and using a managed identity for authentication to Azure SQL Database.
Why the other options are wrong
- B. A service principal with a client secret requires manual management of the secret, which violates the 'should not store any credentials directly' requirement.
- C. A user-assigned managed identity is a standalone Azure resource that can be assigned to multiple resources. While it would work, the question implies a direct, single-resource identity, for which system-assigned is the simpler and often preferred choice for a single app.
- D. Application Gateway identity is not a standard type of managed identity used for authenticating an App Service to a backend database.
System-assigned Managed Identity
An identity created and managed by Azure, tied directly to the lifecycle of a single Azure resource (e.g., App Service, VM). It allows the resource to authenticate to other Azure services without storing credentials in code.
- Automatically created and deleted with the Azure resource.
- Cannot be shared with other resources.
- Credentials are automatically managed and rotated by Azure.
- Simplifies secure access to Azure AD-protected services.
Memory trick: Give your Azure resource its own ID card for secure cloud access.