Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A company is developing a new serverless application using Azure Functions. The application will store customer data in Azure Cosmos DB. Due to strict compliance requirements, all data at rest in Cosmos DB must be encrypted using customer-managed keys (CMK) stored in Azure Key Vault. The Azure Function needs to be able to access the Cosmos DB account, which has been configured to use a system-assigned managed identity. The Cosmos DB account's Key Vault access policy has been configured to grant the Cosmos DB account's managed identity the `Get`, `Wrap Key`, and `Unwrap Key` permissions to the encryption key. Which of the following describes the most secure and appropriate method for the Azure Function to authenticate to Azure Cosmos DB to perform read/write operations?
- ACreate a service principal for the Azure Function, store its client secret in Azure Key Vault, and retrieve it at runtime to authenticate to Cosmos DB.
- BUse an access key directly obtained from the Azure Cosmos DB connection string and store it as an application setting in the Azure Function.
- CEmbed the Cosmos DB primary master key directly within the Azure Function's code during deployment.
- DEnable a system-assigned managed identity for the Azure Function and grant this identity the 'Cosmos DB Built-in Data Contributor' role on the Cosmos DB account.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable a system-assigned managed identity for the Azure Function and grant this identity the 'Cosmos DB Built-in Data Contributor' role on the Cosmos DB account.
Using a system-assigned managed identity for the Azure Function provides an identity that is automatically managed by Azure and tied to the function's lifecycle. Granting this identity the 'Cosmos DB Built-in Data Contributor' role adheres to the principle of least privilege and is a secure, passwordless authentication method.
Why the other options are wrong
- A. While using a service principal and Key Vault is more secure than hardcoding secrets, it involves managing client secrets. Managed identities are a simpler and more secure alternative for Azure resources.
- B. Storing access keys directly as application settings is less secure than managed identities, as it involves managing secrets manually and increases the risk of exposure.
- C. Embedding keys directly in code is a highly insecure practice and should never be done, as it exposes sensitive credentials.
System-Assigned Managed Identity
An identity automatically created and managed by Azure for an Azure resource, eliminating the need for developers to manage credentials.
- Tied to the lifecycle of the Azure resource.
- Automatically authenticated by Azure AD.
- Used for secure, passwordless access to other Azure services.
- Adheres to the principle of least privilege when combined with RBAC.
Memory trick: Functions use their own Azure ID to talk to Cosmos DB securely, without needing passwords.