Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A developer is creating an Azure Function that needs to interact with an Azure Storage Account. To enhance security, the function should authenticate to the storage account using a managed identity. Which type of managed identity should the developer use if the function app is already deployed and needs to share the identity with other Azure resources?
- AService Principal identity
- BSystem-assigned managed identity
- CUser-assigned managed identity
- DApplication Gateway identity
Show answer & explanationAnswer & explanation
Correct answer: C. User-assigned managed identity
User-assigned managed identities are standalone Azure resources that can be assigned to multiple Azure resources, including Function Apps. This allows for sharing the same identity across different services and managing its lifecycle independently of the resource it's assigned to.
Why the other options are wrong
- A. Service Principal identity is the underlying object for both managed identities, but 'User-assigned managed identity' is the specific high-level concept for sharable identities.
- B. System-assigned managed identities are tied to the lifecycle of a single Azure resource and cannot be shared or assigned to multiple resources.
- D. Application Gateway identity is not a standard type of managed identity for authenticating Azure Functions to storage.
User-assigned Managed Identity
A standalone Azure resource that can be assigned to multiple Azure resources to enable them to authenticate to other Azure services without managing credentials.
- Independent lifecycle from the associated resource
- Can be assigned to multiple Azure resources
- Requires explicit creation and assignment
Memory trick: User-assigned: Like a shared key for many doors.