Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium
A global financial institution is deploying a new trading platform to Azure. The platform will interact with various Azure services, including Azure Key Vault for secrets management and Azure SQL Database for transactional data. The security team mandates that all interactions between the platform's services and other Azure resources must be authenticated using a robust, automatically managed identity without storing credentials in code. Which authentication solution should you recommend to meet these requirements?
- AManaged Identities for Azure Resources
- BAzure Active Directory (AAD) application registrations with certificates
- CService Principals with client secrets
- DStoring credentials in environment variables and retrieving them at runtime
Show answer & explanationAnswer & explanation
Correct answer: A. Managed Identities for Azure Resources
Managed Identities for Azure Resources provide an automatically managed identity in Azure Active Directory (Azure AD) for applications to use when connecting to resources that support Azure AD authentication. This eliminates the need for developers to manage credentials, enhancing security and simplifying development.
Why the other options are wrong
- B. AAD application registrations with certificates, while more secure than client secrets, still require certificate management (e.g., rotation, expiration tracking) and do not provide an 'automatically managed' identity in the same seamless way as Managed Identities.
- C. Service principals with client secrets require manual secret management, which is prone to security risks and does not meet the 'automatically managed identity without storing credentials in code' requirement.
- D. Storing credentials in environment variables is insecure, as these can be easily accessed or exposed, violating the security team's mandate against storing credentials in code.
Managed Identities for Azure Resources
Managed Identities provide an automatically managed identity in Azure Active Directory for applications to use when connecting to resources that support Azure AD authentication, eliminating the need for developers to manage credentials.
- Automatic credential management by Azure
- Eliminates storing credentials in code
- Supports two types: System-assigned and User-assigned
- Integrates with Azure AD-aware services
Memory trick: Managed Identity: My App's Invisible Key