Bird
Raised Fist0
Azurecloud~5 mins

Managed identity integration in Azure - Cheat Sheet & Quick Revision

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is a managed identity in Azure?
A managed identity is a feature in Azure that provides an automatically managed identity in Azure Active Directory for applications to use when connecting to resources. It removes the need to manage credentials manually.
Click to reveal answer
beginner
What are the two types of managed identities in Azure?
The two types are:
1. System-assigned managed identity: Enabled directly on an Azure resource and tied to its lifecycle.
2. User-assigned managed identity: Created as a standalone Azure resource and can be assigned to multiple resources.
Click to reveal answer
intermediate
How does a managed identity improve security compared to using service principals with secrets?
Managed identities eliminate the need to store credentials in code or configuration. Azure handles credential rotation automatically, reducing the risk of leaked or expired secrets.
Click to reveal answer
beginner
Which Azure service can use managed identities to authenticate without credentials?
Many Azure services can use managed identities, including Azure Virtual Machines, Azure App Service, Azure Functions, and Azure Logic Apps, to authenticate securely to other Azure services like Key Vault or Storage.
Click to reveal answer
beginner
What is the main step to enable a system-assigned managed identity on an Azure resource?
You enable the system-assigned managed identity in the Azure portal or via CLI by turning on the identity feature for the resource. Azure then creates an identity tied to that resource's lifecycle.
Click to reveal answer
What happens to a system-assigned managed identity when its Azure resource is deleted?
AThe managed identity is transferred to another resource.
BThe managed identity remains and must be deleted manually.
CThe managed identity is deleted automatically.
DThe managed identity becomes inactive but stays in Azure AD.
Which of the following is NOT a benefit of using managed identities?
ANo need to store secrets in code
BManual rotation of credentials required
CAutomatic credential management
DSimplified authentication to Azure services
Which Azure CLI command enables a system-assigned managed identity on a virtual machine named 'vm1'?
Aaz vm identity assign --name vm1 --resource-group myGroup
Baz identity create --name vm1 --resource-group myGroup
Caz vm create --name vm1 --assign-identity
Daz vm identity enable --name vm1 --resource-group myGroup
User-assigned managed identities can be:
ATied to only one resource's lifecycle
BUsed only with Azure Functions
CAutomatically deleted with the resource
DAssigned to multiple Azure resources
Which Azure service is commonly accessed using managed identities for secret retrieval?
AAzure Key Vault
BAzure Cosmos DB
CAzure DevOps
DAzure Monitor
Explain what a managed identity is and why it is useful in Azure.
Think about how apps connect securely without passwords.
You got /4 concepts.
    Describe the difference between system-assigned and user-assigned managed identities.
    Consider how each identity is created and managed.
    You got /4 concepts.

      Practice

      (1/5)
      1. What is the main purpose of using a managed identity in Azure?
      Managed Identity helps your app to:
      easy
      A. Create new Azure subscriptions automatically
      B. Access other Azure services securely without storing credentials
      C. Run virtual machines faster
      D. Manage user passwords in Azure Active Directory

      Solution

      1. Step 1: Understand managed identity purpose

        Managed identities provide apps a way to authenticate to Azure services without needing to store credentials like passwords.
      2. Step 2: Identify correct use case

        Among the options, only accessing services securely without credentials matches the purpose of managed identities.
      3. Final Answer:

        Access other Azure services securely without storing credentials -> Option B
      4. Quick Check:

        Managed identity = secure access without passwords [OK]
      Hint: Managed identity means no passwords needed for service access [OK]
      Common Mistakes:
      • Thinking managed identity speeds up VM performance
      • Confusing managed identity with subscription management
      • Assuming it manages user passwords
      2. Which of the following is the correct way to enable a system-assigned managed identity for an Azure Virtual Machine using Azure CLI?
      easy
      A. az vm identity enable --name MyVM --resource-group MyGroup
      B. az vm create --name MyVM --resource-group MyGroup --assign-identity
      C. az vm identity assign --name MyVM --resource-group MyGroup
      D. az vm identity add --name MyVM --resource-group MyGroup

      Solution

      1. Step 1: Recall Azure CLI command for managed identity

        The correct command to assign a system-assigned managed identity to an existing VM is az vm identity assign.
      2. Step 2: Verify command syntax

        az vm identity assign --name MyVM --resource-group MyGroup uses the correct command and parameters. Other options use incorrect commands or flags.
      3. Final Answer:

        az vm identity assign --name MyVM --resource-group MyGroup -> Option C
      4. Quick Check:

        Assign identity command = az vm identity assign [OK]
      Hint: Use 'az vm identity assign' to enable system-assigned identity [OK]
      Common Mistakes:
      • Using 'az vm create' with wrong flags
      • Using non-existent commands like 'identity enable'
      • Confusing 'assign' with 'add'
      3. Consider this Azure CLI command sequence:
      az vm create --name MyVM --resource-group MyGroup --image UbuntuLTS --assign-identity
      az role assignment create --assignee  --role Reader --scope /subscriptions/123/resourceGroups/MyGroup

      What is the expected result?
      medium
      A. The VM is created with a system-assigned identity and granted Reader role on the resource group
      B. The VM is created without any identity and no role assignment is made
      C. The VM creation fails due to missing identity parameters
      D. The VM is created but the role assignment fails because the principal ID is invalid

      Solution

      1. Step 1: Analyze VM creation command

        The --assign-identity flag creates a system-assigned managed identity for the VM.
      2. Step 2: Analyze role assignment command

        The role assignment grants the identity Reader access to the resource group scope using the identity's principal ID.
      3. Final Answer:

        The VM is created with a system-assigned identity and granted Reader role on the resource group -> Option A
      4. Quick Check:

        Assign identity + role assignment = secure access granted [OK]
      Hint: Assign identity then grant role for access [OK]
      Common Mistakes:
      • Assuming VM creation fails without explicit identity creation
      • Thinking role assignment needs user principal, not identity
      • Ignoring the --assign-identity flag effect
      4. You tried to enable a user-assigned managed identity on an Azure App Service but received an error. Which of the following is the most likely cause?
      medium
      A. The App Service plan is not Premium tier
      B. The App Service already has a system-assigned identity enabled
      C. The user-assigned identity was not created in the same subscription
      D. The user-assigned identity is not assigned to the App Service resource

      Solution

      1. Step 1: Understand user-assigned identity attachment

        User-assigned identities must be explicitly assigned to the resource to be used.
      2. Step 2: Identify common error cause

        If the identity exists but is not assigned to the App Service, enabling it will fail.
      3. Final Answer:

        The user-assigned identity is not assigned to the App Service resource -> Option D
      4. Quick Check:

        User-assigned identity must be assigned to resource [OK]
      Hint: Assign user identity to resource before enabling [OK]
      Common Mistakes:
      • Assuming system-assigned identity conflicts with user-assigned
      • Thinking subscription mismatch causes error
      • Believing App Service plan tier affects identity assignment
      5. You want an Azure Function to access a Key Vault securely using a managed identity. Which steps should you follow to set this up correctly?
      hard
      A. Enable system-assigned identity on the Function, grant it Key Vault access policy, then use identity in code
      B. Create a user-assigned identity, assign it to the Function, then store its secret in Key Vault
      C. Enable system-assigned identity on the Function, store Function credentials in Key Vault, then access Key Vault
      D. Create a user-assigned identity, assign it to the Function, then use a password stored in Key Vault

      Solution

      1. Step 1: Enable system-assigned managed identity on Azure Function

        This allows the Function to authenticate without credentials.
      2. Step 2: Grant the Function's identity access to Key Vault

        Set an access policy in Key Vault to allow the identity to read secrets.
      3. Step 3: Use the managed identity in Function code to access Key Vault

        The Function can request tokens and securely retrieve secrets without passwords.
      4. Final Answer:

        Enable system-assigned identity on the Function, grant it Key Vault access policy, then use identity in code -> Option A
      5. Quick Check:

        Enable identity + grant access + use identity = secure Key Vault access [OK]
      Hint: Enable identity, grant access, then use it in code [OK]
      Common Mistakes:
      • Storing passwords instead of using managed identity
      • Confusing user-assigned identity with storing secrets
      • Not granting Key Vault access to the identity