Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy

A company is developing a new cloud-native application that will be deployed across multiple Azure Kubernetes Service (AKS) clusters in different regions. Each AKS cluster needs to securely access Azure Key Vault to retrieve secrets. The security team requires a solution that minimizes credential management overhead and allows for consistent identity management across all clusters.

  1. AConfigure a system-assigned managed identity for each AKS cluster.
  2. BCreate a single user-assigned managed identity and associate it with all AKS clusters.
  3. CManually store Key Vault access credentials in Kubernetes secrets within each cluster.
  4. DImplement Azure AD application registrations for each AKS cluster.
Show answer & explanation

Correct answer: B. Create a single user-assigned managed identity and associate it with all AKS clusters.

A user-assigned managed identity can be created once and then associated with multiple Azure resources, simplifying credential management and providing a consistent identity across distributed deployments like AKS clusters. This avoids the overhead of managing individual identities per cluster.

Why the other options are wrong

  • A. System-assigned managed identities are created per resource and would require managing multiple identities, increasing overhead.
  • C. Manually storing credentials in Kubernetes secrets is insecure and goes against best practices for secret management and workload identity.
  • D. Azure AD application registrations would require manual credential management (client secrets or certificates) and rotation, increasing complexity.

User-assigned Managed Identity

An Azure identity resource that can be created independently and then assigned to one or more Azure resources. It provides an identity for Azure services to authenticate to other services without needing to manage credentials.

  • Independent lifecycle from the associated resource(s).
  • Can be assigned to multiple resources.
  • Suitable for shared identity scenarios across multiple services.

Memory trick: User-assigned is for UNIFIED access.

More Implement and manage workload identities questions