An application running on an Azure VM must call Azure Key Vault and Azure Storage without any credentials stored in code or configuration. What should the architect design?
- AA shared access key embedded in app settings
- BA service principal with a client secret in code
- CA managed identity for the VM granted access to Key Vault and StorageCorrect
- DA local administrator account on the VM
Why: A managed identity lets the VM authenticate to Entra ID-integrated services with no stored secrets, and you grant it least-privilege access via RBAC. Embedded keys or a client secret in code store credentials that can leak, and a local admin account does not authenticate to Azure services.