Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium

A software development company uses Azure App Service to host several RESTful APIs. These APIs need to securely access data in an Azure SQL Database. To avoid hardcoding credentials and manage identities centrally, the company wants to use a managed identity for authentication between the App Service and the SQL Database. Which type of managed identity should be assigned to the Azure App Service?

  1. AGroup-assigned managed identity
  2. BService principal
  3. CSystem-assigned managed identity
  4. DUser-assigned managed identity
Show answer & explanation

Correct answer: C. System-assigned managed identity

A system-assigned managed identity is created and managed by Azure for a specific resource (like an App Service), automatically handling its lifecycle. This is the simplest way to enable an App Service to authenticate to Azure SQL Database without managing credentials.

Why the other options are wrong

  • A. There is no concept of a 'group-assigned managed identity'.
  • B. A service principal is an identity created for an application in Azure AD, but managed identities simplify this process by automatically managing the service principal's lifecycle and credentials.
  • D. User-assigned managed identities are created as standalone Azure resources and can be assigned to multiple resources, offering more flexibility but more management overhead than a system-assigned one for a single App Service.

System-assigned Managed Identity

An Azure Active Directory identity automatically created and tied to the lifecycle of a single Azure resource, allowing it to authenticate to other Azure services without managing credentials.

  • Tied to one Azure resource.
  • Automatically created and deleted with the resource.
  • Simplifies authentication to Azure services (e.g., Azure SQL, Key Vault).

Memory trick: System-assigned: Your App Service's personal, auto-generated ID card.

More Secure data and applications questions