Granting VM Managed Identity Access to Azure Key Vault
You have an Azure subscription that contains a virtual machine named VM1 and an Azure key vault named Vault1. VM1 has a system-assigned managed identity. You need to ensure that VM1 can retrieve the values of secrets stored in Vault1. The solution must minimize administrative effort. What should you do first?
Community Votes
80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The key insight is that while Key Vault has its own access policies, modern best practice and the 'minimize administrative effort' constraint favor using Azure RBAC roles assigned directly to the managed identity.
This question tests how a system-assigned managed identity on an Azure VM can be granted access to secrets in an Azure Key Vault. The correct approach involves assigning an Azure role to minimize administrative effort.
Many learners choose option B (Configure permissions model) or A (Resource access settings), confusing the legacy access policy mechanism with the newer, simpler RBAC assignment required for managed identities.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To allow VM1's system-assigned managed identity to retrieve secrets from Vault1 with minimal administrative effort, you should assign an Azure role. Specifically, the 'Key Vault Secrets User' role provides the necessary read permission. Assigning a built-in Azure AD role is significantly easier than managing individual access policies, especially as the number of resources grows. This aligns with Microsoft's recommendation to use RBAC over access policies where possible.Why the Other Options Are Wrong
Option A refers to configuring access policies, which is the legacy method. While valid, it requires more manual configuration per resource and does not scale well, violating the 'minimize administrative effort' requirement. Option B suggests changing the vault's overall permissions model, which is vague and not a direct action to grant specific access. Option C is unnecessary because the VM already has a system-assigned managed identity, which is sufficient for this scenario.Community Comment Notes
Commenters generally agree that assigning a role is the correct path. One user noted, "we can use RBAC or access policy, but to do that we also have to configure the resource... so it is either A or D," highlighting the confusion between the two methods. Another user confirmed that assigning a role allows the managed identity to authenticate without storing credentials, reinforcing the simplicity of the RBAC approach.Official Reference
Exam Strategy
When asked to minimize administrative effort for granting access to managed identities, always prefer Azure RBAC roles over legacy access policies. Roles are centrally managed and apply automatically to all secrets within the vault.
Frequently Asked Questions
Why not use access policies instead of roles?
Access policies require manual configuration per secret and do not scale well. Roles are centralized and easier to manage.
Does the system-assigned managed identity need creation?
No, the VM already has a system-assigned managed identity. You only need to assign it the appropriate role.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →