Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A software development company uses Azure App Service to host several RESTful APIs. These APIs need to securely access secrets (e.g., database connection strings, API keys) stored in Azure Key Vault. The company wants to implement the most secure and recommended method for App Service to authenticate to Key Vault without storing any credentials in the application code or configuration files. Which method should be used?
- AEnable Managed Identities for Azure resources (System-assigned) on the App Service.
- BConfigure a Service Principal for the App Service and store its credentials in App Service settings.
- CStore Key Vault access keys directly in the App Service application settings.
- DUse an access policy in Key Vault to grant permissions to the App Service's IP address.
Show answer & explanationAnswer & explanation
Correct answer: A. Enable Managed Identities for Azure resources (System-assigned) on the App Service.
Managed Identities for Azure resources (System-assigned) eliminate the need to manage credentials, providing a secure and recommended way for App Service to authenticate to Azure Key Vault.
Why the other options are wrong
- B. Service Principals require credential management, which Managed Identities aim to eliminate for improved security.
- C. Storing access keys directly in application settings is insecure and defeats the purpose of using Key Vault.
- D. IP-based access policies are less secure and flexible than Managed Identities, especially for dynamic IP addresses.
Managed Identities for Azure resources
A feature of Azure Active Directory that provides Azure services with an automatically managed identity in Azure AD, allowing them to authenticate to other services that support Azure AD authentication without managing credentials.
- Eliminates the need for developers to manage credentials.
- Identities are managed by Azure AD.
- Supports system-assigned and user-assigned types.
Memory trick: Managed Identities: Azure's handshake to Key Vault.