Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium

A DevOps team is developing a new serverless application using Azure Functions. The application needs to access sensitive data stored in an Azure Key Vault and a backend API hosted in an Azure App Service. Both the Key Vault and the App Service are configured to only allow access from specific Virtual Networks (VNets). How should the DevOps team configure the Azure Function to securely access these resources while adhering to the VNet access restrictions?

  1. AEnable Managed Identities for the Azure Function and grant them access to Key Vault and App Service.
  2. BConfigure Virtual Network integration for the Azure Function and route all outbound traffic through the VNet.
  3. CImplement a public IP address for the Azure Function and add it to the Key Vault and App Service firewall rules.
  4. DDeploy the Azure Function to a dedicated App Service Environment (ASE) within the VNet.
Show answer & explanation

Correct answer: B. Configure Virtual Network integration for the Azure Function and route all outbound traffic through the VNet.

Virtual Network integration for Azure Functions allows the function app to access resources within a VNet or resources connected to a VNet via service endpoints or private endpoints. By routing all outbound traffic through the VNet, the Function's requests will originate from within the VNet, satisfying Key Vault and App Service VNet access restrictions.

Why the other options are wrong

  • A. Managed Identities provide authentication but don't address network-level access restrictions like VNet integration.
  • C. Azure Functions do not typically have static public IP addresses for egress that can be directly added to firewalls, and this approach bypasses VNet restrictions.
  • D. While an ASE provides VNet isolation, it's a much more complex and expensive solution than simple VNet integration for a standard Azure Function app.

Azure Functions VNet Integration

Enabling an Azure Function app to access resources within or connected to an Azure Virtual Network (VNet).

  • Allows outbound traffic from Function to VNet resources.
  • Supports both VNet-restricted resources and private endpoints.
  • Function itself remains publicly accessible by default (inbound).

Memory trick: Functions need VNet integration to 'walk' inside the network and reach restricted doors.

More Develop a security and compliance plan questions