Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A software development company is building a new microservices-based application on Azure Kubernetes Service (AKS). Each microservice requires access to various Azure resources, such as Azure Key Vault for secrets and Azure Storage for data. The security team wants to eliminate the need for developers to manage and embed connection strings or secrets directly within the application code or configuration files. The solution must provide secure, automatic authentication for each microservice to its designated Azure resources based on its identity. Which Azure identity feature should the architect recommend for AKS microservices?

  1. AKubernetes Secrets
  2. BService Principals
  3. CManaged Identities for Azure Resources
  4. DAzure AD Application Registrations
Show answer & explanation

Correct answer: C. Managed Identities for Azure Resources

Managed Identities for Azure Resources provides an identity for an Azure resource (like an AKS pod/microservice) that can authenticate to Azure AD-supported services without managing credentials. This eliminates the need to store secrets in code, making it ideal for secure, automatic authentication from AKS microservices to other Azure services.

Why the other options are wrong

  • A. Kubernetes Secrets are used to store sensitive information within Kubernetes, but they are still secrets that need to be managed and rotated, and they don't provide automatic authentication to Azure AD-protected services without further configuration.
  • B. Service Principals are identities used by applications or services to access resources, but they require manual management of client secrets or certificates, which the requirement aims to eliminate.
  • D. Azure AD Application Registrations define an application's identity in Azure AD, but they are typically used in conjunction with service principals and still require credential management.

Managed Identities for Azure Resources

An Azure AD feature that provides an automatically managed identity for Azure resources, allowing them to authenticate to services that support Azure AD authentication without requiring developers to manage credentials.

  • Eliminates the need for explicit credential management (secrets, certificates).
  • Supports both system-assigned and user-assigned identities.
  • Integrates with many Azure services for seamless authentication.

Memory trick: Managed Identities give AKS microservices their own ID card, so they don't need to carry secrets.

More Design security for applications and data questions