Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard
A company is migrating several legacy on-premises applications to Azure. These applications currently rely on service accounts stored in on-premises Active Directory for authentication to various resources. The security team wants to move away from storing credentials in code or configuration files in Azure. They also require that the identities used by these applications are automatically managed by Azure and tied to the lifecycle of the application's hosting resource. Which identity solution should be implemented for these applications?
- AAzure AD application registrations
- BSystem-assigned managed identities
- CAzure AD service principals
- DUser-assigned managed identities
Show answer & explanationAnswer & explanation
Correct answer: B. System-assigned managed identities
System-assigned managed identities create an identity for an Azure resource that is tied to its lifecycle, automatically managed by Azure, and eliminates the need to store credentials, directly meeting all stated requirements.
Why the other options are wrong
- A. Application registrations are the definition of an application in Azure AD, from which service principals are created. This is a foundational element but not the specific identity solution for credential-free and lifecycle-managed identities.
- C. Service principals are identities for applications in Azure AD, but they often require manual credential management (client secrets/certificates) and are not automatically tied to the lifecycle of a specific resource in the same way.
- D. User-assigned managed identities are separate Azure resources that can be assigned to multiple resources. While they eliminate credential management, the scenario emphasizes being 'tied to the lifecycle of the application's hosting resource', which points more directly to system-assigned.
System-assigned Managed Identity
A system-assigned managed identity provides an Azure Active Directory identity for an Azure resource. Its lifecycle is tied directly to the resource, and Azure automatically manages its credentials.
- Enabled directly on an Azure service (e.g., VM, App Service).
- Lifecycle is tied to the parent resource; deleted when resource is deleted.
- Azure automatically manages the identity's credentials.
- Cannot be shared with other resources.
Memory trick: System-Assigned: Stuck to the System, Secure by Design.