Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A company is developing an Azure Function that processes orders. The function needs to connect to an Azure SQL Database. To ensure the connection is secure and uses the principle of least privilege, which connection string component should be avoided, and what is the best practice for secure access?
- AAvoid `Timeout=30`; use a long connection string with all possible parameters.
- BAvoid `Encrypt=False`; use a public IP address for the database.
- CAvoid embedding username/password directly; use a Managed Identity for the Function App.
- DAvoid `Integrated Security=True`; use SQL Authentication with a stored password.
Show answer & explanationAnswer & explanation
Correct answer: C. Avoid embedding username/password directly; use a Managed Identity for the Function App.
Embedding usernames and passwords directly in connection strings or application code is a security risk. The best practice is to use Managed Identities for Azure resources, such as Function Apps. This allows the Function App to authenticate to Azure SQL Database using its Azure AD identity, eliminating the need for explicit credentials in the connection string.
Why the other options are wrong
- A. `Timeout` is a functional parameter, not a security risk, and a long connection string is not a security best practice.
- B. `Encrypt=False` is insecure, but using a public IP address for the database is also insecure and unrelated to the connection string component to avoid.
- D. Integrated Security (Windows Authentication) is for on-premises AD; SQL Authentication with stored password still exposes credentials.
Managed Identity for Azure Services
An Azure Active Directory feature that provides Azure services with an automatically managed identity in Azure AD, allowing them to authenticate to other Azure services without needing to store credentials.
- Eliminates credential management for developers
- Based on Azure AD authentication
- Supports system-assigned and user-assigned identities
Memory trick: Managed Identity: No password, just trust.