Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium

A company is developing a microservices application using Azure Kubernetes Service (AKS). Each microservice needs to securely access specific Azure resources (e.g., Azure Storage, Azure Key Vault) without sharing credentials or using a single, highly privileged identity for the entire cluster. The security team mandates that each pod should have its own distinct identity for authentication. Which AKS feature should the developer leverage?

  1. AService Accounts
  2. BAzure AD Workload Identity
  3. CKubernetes Secrets
  4. DPod Security Policies
Show answer & explanation

Correct answer: B. Azure AD Workload Identity

Azure AD Workload Identity (formerly Azure AD Pod Identity) allows Kubernetes pods to access Azure resources securely using an Azure Active Directory identity. This feature assigns an Azure AD identity to a pod, enabling it to authenticate to Azure resources using AAD, fulfilling the requirement for distinct pod identities without shared credentials.

Why the other options are wrong

  • A. Service Accounts provide an identity for processes that run in a pod, but they are Kubernetes-native and do not directly map to Azure AD identities for accessing Azure resources.
  • C. Kubernetes Secrets are used to store sensitive data like passwords or API keys within the cluster, but they still require manual management and don't provide an AAD identity for the pod.
  • D. Pod Security Policies (deprecated in Kubernetes 1.25, replaced by Pod Security Admission) enforce security standards for pods and do not provide identity-based access to Azure resources.

Azure AD Workload Identity

An AKS feature that enables Kubernetes pods to authenticate to Azure resources using Azure Active Directory identities, providing fine-grained, distinct identities for each workload.

  • Maps Kubernetes Service Accounts to Azure AD identities.
  • Eliminates the need for client secrets, certificates, or Managed Identities for the entire cluster.
  • Enhances security by providing least-privilege access for individual pods.

Memory trick: Workload Identity gives each pod its own Azure AD ID badge.

More Implement Azure security questions