A global manufacturing company has multiple Azure subscriptions, each managed by a different regional team. A central IT team manages a set of shared Azure Key Vaults in a 'central' subscription that contain configuration secrets for applications deployed across all regional subscriptions. An Azure Function App in a 'Europe' subscription needs to access a secret in a Key Vault located in the 'central' subscription. Which workload identity solution allows the Function App to securely access the Key Vault without sharing credentials between subscriptions?
- AUse an Azure AD Application Registration with a client secret and store it securely in the Function App's configuration.
- BCreate a user-assigned managed identity in the 'central' subscription and assign it to the Function App.
- CCreate a user-assigned managed identity in the 'Europe' subscription and grant it Key Vault access in the 'central' subscription.
- DConfigure a system-assigned managed identity for the Function App and grant it Key Vault access.
Show answer & explanationAnswer & explanation
Correct answer: C. Create a user-assigned managed identity in the 'Europe' subscription and grant it Key Vault access in the 'central' subscription.
To enable cross-subscription access with managed identities, the user-assigned managed identity should be created in the same subscription as the resource (Function App in 'Europe') that needs to access the target resource (Key Vault in 'central'). Then, the access policy (RBAC) to the Key Vault should be granted to this user-assigned managed identity in the 'central' subscription.
Why the other options are wrong
- A. Using an Application Registration with a client secret requires manual credential management and rotation, which is less secure and more complex than managed identities, and doesn't solve the cross-subscription access elegantly without credential sharing.
- B. Creating the user-assigned managed identity in the 'central' subscription makes it difficult to assign it to a resource in the 'Europe' subscription. Managed identities are typically assigned to resources within the same subscription or a linked subscription.
- D. System-assigned managed identities are scoped to the resource's subscription and cannot be directly used for cross-subscription access without complex RBAC configuration across tenants, which is not the primary use case.
Cross-Subscription Managed Identity Access
Enabling an Azure resource in one subscription to authenticate and access another Azure resource in a different subscription using a managed identity. This is typically achieved by creating a user-assigned managed identity in the source subscription and granting it RBAC permissions on the target resource in the destination subscription.
- User-assigned managed identities are preferred for cross-subscription scenarios.
- Managed identity is created in the same subscription as the accessing resource.
- RBAC permissions are granted on the target resource (in the other subscription) to this managed identity.
Memory trick: IDENTITY lives LOCAL, ACCESS is GLOBAL.