Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A developer is building an Azure Function App that needs to securely access secrets stored in Azure Key Vault. The Function App is deployed to an Azure App Service Plan. The developer wants to avoid hardcoding credentials and ensure that the Function App can authenticate to Key Vault automatically using its own identity. Which authentication method should the developer implement?
- AShared Access Signature (SAS) token
- BAzure Active Directory (AAD) user authentication
- CManaged Identity
- DService principal with a client secret
Show answer & explanationAnswer & explanation
Correct answer: C. Managed Identity
Managed Identities for Azure resources provide an automatically managed identity in Azure Active Directory for Azure services. This allows the Function App to authenticate to services like Azure Key Vault without needing to manage credentials, aligning with the requirement to avoid hardcoding credentials and use its own identity.
Why the other options are wrong
- A. SAS tokens are primarily used for delegating access to Azure Storage resources, not for authenticating an Azure Function to Key Vault.
- B. AAD user authentication is typically for interactive user sign-ins, not for service-to-service authentication for an Azure Function.
- D. Service principals with client secrets require manual secret management and rotation, which the developer wants to avoid.
Managed Identity
An Azure Active Directory identity automatically managed by Azure, allowing Azure services to authenticate to cloud services without requiring developers to manage credentials.
- Eliminates the need for storing credentials in code or configuration files.
- Supports two types: System-assigned (tied to a single resource) and User-assigned (can be used by multiple resources).
- Used for authenticating to any service that supports Azure AD authentication.
Memory trick: Managed Identity: The robot's built-in key for Azure services.