AZ-802 Manage Windows Server in a Hybrid Environment Practice Question
When onboarding servers to Azure Arc, which type of identity is automatically created for the server?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
System-assigned managed identity
Azure Arc-enabled servers are assigned a system-assigned managed identity. This identity is managed by the Azure platform and is tied to the lifecycle of the Arc resource. It allows the server to authenticate securely to other Azure services (like Key Vault or Log Analytics) without requiring hardcoded credentials, significantly enhancing the security posture of the hybrid environment by removing the need for secret management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User-assigned managed identity
Why it's wrong here
User-assigned managed identities are manually created and managed by the user, rather than being automatically created by the platform upon resource onboarding. While they can be assigned to Arc-enabled servers, they are not the default identity type that is automatically generated during the initial Arc onboarding process.
- ✓
System-assigned managed identity
Why this is correct
The system-assigned managed identity is automatically generated by Azure when you onboard a machine to Azure Arc. This identity is linked to the Azure resource and allows the machine to authenticate to cloud services, providing a secure, platform-managed alternative to traditional service principals or stored credentials.
- ✗
Active Directory service account
Why it's wrong here
Active Directory service accounts are local or domain-based identities and are not automatically created or managed by Azure Arc. Azure Arc works with the machine's cloud identity, which is distinct from on-premises AD accounts, ensuring that hybrid identity management remains separate from internal directory services for enhanced security.
- ✗
Azure AD guest identity
Why it's wrong here
Azure AD guest identities are for external users accessing your tenant resources and are not relevant for server-based authentication. Server identities are specific to machine-to-service communication, not user access, making the guest identity model inappropriate for the operational requirements of an Azure Arc-enabled hybrid server.
About these practice questions
This AZ-802 question is part of Courseiva's 116-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.