Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A client is migrating an on-premises application to Azure. The application currently uses an on-premises SQL Server database and authenticates using Windows Integrated Authentication. The new architecture will host the application on an Azure App Service and the database on Azure SQL Database. The security team insists that the application should not store any credentials. How should the application authenticate to Azure SQL Database while adhering to the security team's requirement?
- AEmbed the SQL connection string directly in the App Service configuration, protected by App Service access controls.
- BUse an Azure Key Vault to store the SQL connection string and retrieve it at runtime.
- CImplement a custom token-based authentication mechanism between App Service and SQL Database.
- DConfigure AAD-authenticated SQL users and use a system-assigned managed identity for the App Service.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure AAD-authenticated SQL users and use a system-assigned managed identity for the App Service.
Using a system-assigned managed identity for the Azure App Service allows it to authenticate to Azure SQL Database using its own identity in Azure AD, eliminating the need to store any credentials within the application or App Service configuration.
Why the other options are wrong
- A. Embedding connection strings, even protected, still involves storing credentials, which violates the security team's 'should not store any credentials' requirement.
- B. Key Vault stores credentials securely, but the application still needs a way to authenticate to Key Vault, potentially requiring a stored credential or managed identity, making it a less direct solution for SQL.
- C. Custom token-based authentication adds unnecessary complexity and requires significant development effort, while a native Azure solution exists.
Managed Identities for Azure Resources
Managed Identities provide an Azure Active Directory identity for Azure services, eliminating the need for developers to manage credentials by allowing services to authenticate to other Azure AD-protected services.
- System-assigned: Tied to the lifecycle of a single Azure resource.
- User-assigned: Created as a standalone Azure resource, can be assigned to multiple resources.
- Simplifies authentication to Azure services like Key Vault, Storage, and SQL Database.
Memory trick: Identity Manages Access, No Need for Stored Secrets.