A web app uses Azure Key Vault to store secrets. The app runs in a production environment and needs to authenticate to Key Vault without storing connection strings in configuration files. Which authentication method should be used?
Managed identity provides an automatically managed identity in Azure Active Directory (AAD) for Azure services, enabling them to authenticate to other AAD-protected services like Key Vault without requiring developers to manage any credentials. Azure automatically handles the creation, rotation, and secure provisioning of these identities, eliminating the need for secrets in application code or configuration. This approach significantly enhances security by removing the burden of credential management and reducing the attack surface.
Why this answer
Managed identity (Option B) is correct because it allows the web app to authenticate to Azure Key Vault without storing any credentials in code or configuration files. Azure automatically manages the identity for the app, and the app uses the Azure Identity SDK to obtain tokens via the Azure Instance Metadata Service (IMDS) endpoint, which eliminates the need for connection strings or secrets.
Exam trap
The trap here is that candidates may choose a certificate stored in Key Vault (Option D) thinking it is more secure, but they overlook that managed identity eliminates the need to manage any credential at all, which is the core requirement of the question.
How to eliminate wrong answers
Option A is wrong because storing a client secret in app settings violates the requirement of not storing connection strings in configuration files, and it introduces a security risk of secret leakage. Option C is wrong because storage account access keys are used for authenticating to Azure Storage, not for authenticating to Key Vault, and they would also need to be stored in configuration. Option D is wrong because while a certificate stored in Key Vault can be used for authentication, it still requires the app to have a mechanism to retrieve and use that certificate, which typically involves storing a client ID or other identifier in configuration, and it does not eliminate the need for credential management as effectively as managed identity.