Securely Store API Keys in Azure Key Vault for Logic Apps
Your company uses Azure Logic Apps to automate a business process. The process needs to call an external REST API that requires an API key passed in the Authorization header. You need to store the API key securely and reference it in the Logic App. Which approach should you use?
⚠ Common exam trap
Many candidates choose Option A or C because they think storing the key in the Logic App definition or a parameter file is 'secure enough' for development, but the exam emphasizes that any plaintext storage in code or configuration is a security violation, and the only correct approach is to use a dedicated secrets store like Key Vault with managed identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an Azure Key Vault secret and a managed identity
Azure Key Vault securely stores secrets like API keys, and using a managed identity allows the Logic App to authenticate to Key Vault without embedding credentials in code or configuration. This follows the principle of least privilege and eliminates the need to manage secrets in connection strings or parameter files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the API key in the Logic App's definition as a constant
Why it's wrong here
Storing an API key directly within a Logic App's definition as a constant is highly insecure. This practice embeds sensitive data directly into the application's configuration file, which is typically committed to source control systems. Consequently, the API key becomes exposed in plaintext to anyone with access to the repository, lacking any form of encryption, access control, or auditing capabilities at runtime.
- ✓
Use an Azure Key Vault secret and a managed identity
Why this is correct
Utilizing an Azure Key Vault secret in conjunction with a managed identity is the most secure and recommended approach for handling API keys. Azure Key Vault provides a centralized, secure store for secrets, backed by FIPS 140-2 Level 2 validated hardware security modules (HSMs), offering encryption, versioning, and granular access policies. A managed identity allows the Logic App to authenticate to Key Vault using Microsoft Entra ID without needing any hardcoded credentials, adhering to the principle of least privilege and simplifying secret rotation.
- ✗
Hardcode the API key in a parameter file
Why it's wrong here
Hardcoding an API key within a parameter file, such as those used for Azure Resource Manager (ARM) templates, presents significant security risks. While external to the main definition, these parameter files are still typically stored in code repositories and deployed alongside the application. This means the API key is exposed in plaintext within source control, lacks runtime protection, and offers no built-in mechanisms for secure rotation, auditing, or fine-grained access control, making it vulnerable to unauthorized access.
- ✗
Use an Azure Storage account table to store the key
Why it's wrong here
Using an Azure Storage account table to store an API key is inappropriate for secret management and introduces substantial security vulnerabilities. Azure Storage tables are designed for general-purpose structured data storage, not for sensitive secrets. They lack the specialized security features of Key Vault, such as hardware-backed encryption, secret versioning, expiration, soft-delete, and robust access policies specifically tailored for secrets, making them an insecure choice for protecting API keys.
Go deeper
Related to this question
Learn chapter
Managed Identities in Code
Key term
Managed identity
A managed identity is an automatically managed service principal in Azure that allows your code to authenticate to any service that supports Microsoft Entra ID authentication without storing credentials.
Key term
Key Vault Secrets
Key Vault Secrets are secure containers in Microsoft Azure that store sensitive information like passwords, connection strings, and API keys, keeping them encrypted and accessible only to authorized applications and users.
About these practice questions
Courseiva writes every AZ-204 question from scratch — 883 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on AZ-204
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Azure Logic Apps to integrate with a third-party CRM system. The CRM API requires OAuth 2.0 authentication. The developer needs to securely store the client secret and refresh token. Which Azure service should the developer use?
medium- A.Azure App Configuration
- ✓ B.Azure Key Vault
- C.Azure Managed Identity
- D.Azure SQL Database
Why B: Azure Key Vault is the correct service because it provides a secure, centralized store for secrets such as client secrets and refresh tokens. By storing these sensitive values in Key Vault, the developer can reference them in the Logic App workflow using the Key Vault connector, ensuring that secrets are never exposed in code or configuration. This aligns with the OAuth 2.0 requirement to protect long-lived credentials like refresh tokens.
Variation 2. You are using Azure Logic Apps to integrate with a third-party CRM. The CRM API requires OAuth 2.0 authentication with a client secret. The secret must be stored securely and rotated automatically. What should you do?
medium- A.Use a system-assigned managed identity without storing the secret
- ✓ B.Store the secret in Azure Key Vault and use a managed identity to access it
- C.Store the secret in the Logic App definition as a string parameter
- D.Store the secret in Azure App Configuration with encryption
Why B: Azure Key Vault is the recommended service for storing secrets, and a managed identity allows the Logic App to authenticate to Key Vault without embedding credentials. The Logic App can then retrieve the client secret at runtime, and Key Vault supports automatic rotation via versioning and rotation policies. This satisfies both secure storage and automatic rotation requirements.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.