Granting VM Managed Identity Access to Azure Key Vault

Plan and implement identities for applications and Azure workloads
Answer Correct answer: D — Assign an Azure role to VM1 to grant its managed identity permission to read secrets from Vault1.

You have an Azure subscription that contains a virtual machine named VM1 and an Azure key vault named Vault1. VM1 has a system-assigned managed identity. You need to ensure that VM1 can retrieve the values of secrets stored in Vault1. The solution must minimize administrative effort. What should you do first?

  1. Configure the Resource access settings for Vault1.
  2. Configure the permissions model for Vault1.
  3. Add a user-assigned managed identity to VM1.
  4. Assign an Azure role to VM1. Correct Answer

Community Votes

D
80%
B
20%

80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The key insight is that while Key Vault has its own access policies, modern best practice and the 'minimize administrative effort' constraint favor using Azure RBAC roles assigned directly to the managed identity.

This question tests how a system-assigned managed identity on an Azure VM can be granted access to secrets in an Azure Key Vault. The correct approach involves assigning an Azure role to minimize administrative effort.

Many learners choose option B (Configure permissions model) or A (Resource access settings), confusing the legacy access policy mechanism with the newer, simpler RBAC assignment required for managed identities.

Community Discussion (3 comments)

rvln7 👍 2 Selected: D
stupid question, we can use RBAC or access policy, but to do that we also have to configure the resource (key vault) access settings. so it is either A or D https://learn.microsoft.com/en-us/azure/frontdoor/managed-identity "Configure Key Vault access You can configure Azure Key Vault access using either of the following methods: Role-based access control (RBAC) - Provides fine-grained access control using Azure Resource Manager. Access policy - Uses native Azure Key Vault access control. For more information, see Azure role-based access control (Azure RBAC) vs. access policy."
ethhacker 👍 1 Selected: B
Secrets User, can also be configured directly on vault, would be a more fine grained solution.
Shingie 👍 2 Selected: D
Correct Answer: D. Assign an Azure role to VM1 Explanation: VM1 has a system-assigned managed identity, which allows it to authenticate to Azure resources without storing credentials. However, by default, it does not have permissions to access Vault1. To allow VM1 to retrieve secrets from Vault1, you must assign it an Azure role with appropriate permissions to Key Vault.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To allow VM1's system-assigned managed identity to retrieve secrets from Vault1 with minimal administrative effort, you should assign an Azure role. Specifically, the 'Key Vault Secrets User' role provides the necessary read permission. Assigning a built-in Azure AD role is significantly easier than managing individual access policies, especially as the number of resources grows. This aligns with Microsoft's recommendation to use RBAC over access policies where possible.

Why the Other Options Are Wrong

Option A refers to configuring access policies, which is the legacy method. While valid, it requires more manual configuration per resource and does not scale well, violating the 'minimize administrative effort' requirement. Option B suggests changing the vault's overall permissions model, which is vague and not a direct action to grant specific access. Option C is unnecessary because the VM already has a system-assigned managed identity, which is sufficient for this scenario.

Community Comment Notes

Commenters generally agree that assigning a role is the correct path. One user noted, "we can use RBAC or access policy, but to do that we also have to configure the resource... so it is either A or D," highlighting the confusion between the two methods. Another user confirmed that assigning a role allows the managed identity to authenticate without storing credentials, reinforcing the simplicity of the RBAC approach.

Official Reference

Exam Strategy

When asked to minimize administrative effort for granting access to managed identities, always prefer Azure RBAC roles over legacy access policies. Roles are centrally managed and apply automatically to all secrets within the vault.

Frequently Asked Questions

Why not use access policies instead of roles?

Access policies require manual configuration per secret and do not scale well. Roles are centralized and easier to manage.

Does the system-assigned managed identity need creation?

No, the VM already has a system-assigned managed identity. You only need to assign it the appropriate role.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide