You are planning to deploy an Azure AI Services multi-service resource. You need to ensure that the resource can be used by applications running in an Azure Kubernetes Service (AKS) cluster without embedding keys in the application code. What should you do?
Workload Identity (or the older Pod Identity) allows Kubernetes pods to use a managed identity to authenticate to Azure services. By assigning the Cognitive Services User role to that identity on the Azure AI Services resource, the application can obtain a token from Microsoft Entra ID and call the service without any keys. This meets the keyless requirement.
Why this answer
To enable keyless authentication for applications in AKS, you should use Azure AD Workload Identity (or Pod Identity) to associate a managed identity with the pods. That identity must be granted the Cognitive Services User role on the Azure AI Services resource. The application can then use DefaultAzureCredential to obtain a token and call the service without any keys.
Exam trap
The trap here is assuming that enabling a managed identity on the AKS cluster is enough, when in fact you must configure workload identity to make that identity available to the pods.