Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityEasy
A company is developing a new web application that will be hosted on Azure App Service. The application needs to securely store and retrieve secrets from Azure Key Vault. The security policy dictates that the application should not manage any credentials (like client IDs or client secrets) for authenticating to Key Vault. Which authentication mechanism should the developer configure for the App Service to access Azure Key Vault?
- AConnection strings directly embedded in the App Service configuration.
- BA system-assigned managed identity for the App Service.
- CAzure Active Directory application registration with a client secret.
- DA user-assigned managed identity and a service principal.
Show answer & explanationAnswer & explanation
Correct answer: B. A system-assigned managed identity for the App Service.
A system-assigned managed identity for the App Service provides an identity automatically managed by Azure. This identity can then be granted permissions to Azure Key Vault, allowing the App Service to authenticate to Key Vault without needing to store or manage any explicit credentials (like client secrets) in the application or its configuration.
Why the other options are wrong
- A. Embedding connection strings (which often contain secrets) directly is highly insecure and violates the principle of not managing credentials.
- C. Using a client secret means managing a secret, which the policy explicitly forbids.
- D. While user-assigned managed identities are also secretless, a system-assigned identity is simpler when a single identity tied to the resource's lifecycle is sufficient. A service principal *with a client secret* would violate the policy.
App Service Managed Identity
An Azure Active Directory identity automatically managed by Azure for an Azure App Service, enabling it to authenticate to other Azure services without developers managing credentials.
- Eliminates the need for API keys or client secrets.
- Tied to the lifecycle of the App Service.
- Authenticates to Azure AD-protected resources (e.g., Key Vault, Storage).
- Supports both system-assigned and user-assigned types.
Memory trick: App Service uses its own Managed ID to get secrets from Key Vault.