Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy

A software development company uses Azure App Service to host several RESTful APIs. These APIs need to securely access data stored in an Azure Storage Account. The company wants to avoid hard-coding credentials or managing secrets directly in the application code. They also require that the identity used to access the storage account is automatically managed by Azure. Which authentication mechanism should be implemented?

  1. AOAuth 2.0 with client secrets.
  2. BAzure Key Vault with application-managed secrets.
  3. CManaged Identities for Azure resources.
  4. DShared Access Signatures (SAS) for the storage account.
Show answer & explanation

Correct answer: C. Managed Identities for Azure resources.

Managed Identities for Azure resources provide an automatically managed identity in Azure Active Directory (Azure AD) for applications to use when connecting to resources that support Azure AD authentication. This eliminates the need for developers to manage credentials.

Why the other options are wrong

  • A. OAuth 2.0 with client secrets requires manual secret management, which the company wants to avoid.
  • B. While Azure Key Vault is for secure secret storage, using application-managed secrets still requires the application to retrieve and manage the secret, which Managed Identities abstract away.
  • D. SAS tokens are credentials that need to be managed and rotated, which the company wants to avoid.

Managed Identities for Azure resources

A feature of Azure Active Directory that provides Azure services with an automatically managed identity in Azure AD. You can use this identity to authenticate to any service that supports Azure AD authentication, without managing any credentials in your code.

  • Eliminates credential management for developers.
  • Automatically managed by Azure AD.
  • Supports authentication to Azure AD-enabled services.

Memory trick: Managed Identities are like a 'robot butler' for secrets, handling them automatically.

More Secure data and applications questions