Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A company is developing an Azure API Management (APIM) instance that exposes several backend APIs. These backend APIs are hosted on Azure App Services and are secured using Azure Active Directory authentication. The APIM instance needs to authenticate to the backend APIs using its own identity, without exposing any credentials to the APIM policy. Which mechanism should the developer use to enable APIM to securely authenticate to the backend App Services?
- AEmbed the App Service API keys directly into the APIM policy for each backend API.
- BConfigure the APIM instance with a system-assigned managed identity and grant it permissions to the App Services.
- CUse a shared access signature (SAS) token generated for each App Service and embed it in the APIM policy.
- DStore the App Service client ID and client secret in APIM named values and reference them in an `authentication-managed-identity` policy.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure the APIM instance with a system-assigned managed identity and grant it permissions to the App Services.
Configuring APIM with a system-assigned managed identity provides an Azure AD identity for the APIM instance itself. This identity can then be granted permissions to access other Azure AD-protected resources, like App Services, without managing any secrets. The `authentication-managed-identity` policy in APIM can then leverage this identity to obtain an access token.
Why the other options are wrong
- A. Embedding API keys directly in policies is insecure as it hardcodes credentials, making them difficult to rotate and prone to exposure.
- C. SAS tokens are primarily for storage accounts or Service Bus, not for authenticating to Azure App Services secured with Azure AD.
- D. Named values are good for storing secrets, but using a client secret means managing a secret. A managed identity is a more secure, secretless approach for Azure-to-Azure communication.
APIM Managed Identity
Azure API Management can use a system-assigned or user-assigned managed identity to authenticate to other Azure services that support Azure AD authentication.
- Eliminates the need for API keys or client secrets.
- Leverages Azure AD for authentication and authorization.
- Used in conjunction with `authentication-managed-identity` policy.
- Enhances security by providing a secretless authentication mechanism.
Memory trick: APIM needs its own ID to securely talk to App Services.