Azure security is one of the core domains in the AZ-204 exam. It covers a wide range: app registration through Microsoft Identity Platform, acquiring tokens with MSAL, using Microsoft Graph API, credential-free access with Managed Identity, managing secrets with Key Vault, and centralized configuration with App Configuration.
Microsoft Identity Platform and App Registration
App registration is the process of registering an application with Azure AD (Entra ID). Think of hotel check-in as an example. To stay at the hotel (Azure AD), you need to register in the reservation system. Once registered, you receive a guest ID (client ID) that you use to access services.
You must understand the key components of app registration.
| Component | Description | Example | |-----------|-------------|---------| | Client ID (Application ID) | Unique UUID identifying the app | 550e8400-e29b-41d4-a716-... | | Tenant ID (Directory ID) | UUID identifying the Azure AD organization | Different UUID per organization | | Redirect URI | URL to redirect users to after authentication | https://myapp.com/auth/callback | | Client Secret | Password used by the app (has expiration) | Generated directly, must be stored safely | | Certificate | Safer alternative to client secret | Upload PEM/CER file |
Important distinction: Both client secrets and certificates are used for app authentication, but certificates are safer. On the exam, choose certificates as the "more secure method."
MSAL: A Library That Makes Token Management Easy
MSAL (Microsoft Authentication Library) is an authentication library provided by Microsoft so developers don't have to implement OAuth 2.0/OpenID Connect protocols themselves. Think of a ride-sharing app as an example. You could find your own route, but the app handles all routing and fare calculation for you. MSAL handles token acquisition, renewal, and caching.
Key Features
Token acquisition: Obtain access tokens via user login (delegated permission) or the app itself (application permission) Token cache: Store already-issued tokens and reuse them until expiration (prevents unnecessary logins) Token renewal: Automatically use refresh tokens to issue new access tokens when expired Various auth flows: Provides appropriate flows for web apps, desktop apps, mobile apps, and background services
Permission Types
| Permission Type | Description | When to Use | |-----------------|-------------|------------| | Delegated | Acts on behalf of a logged-in user | Apps with users (web app, mobile) | | Application | App itself acts without a user | Background services, daemons |
On the exam, distinguish: "services running without a user" use application permission, "actions on behalf of users" use delegated permission.
Microsoft Graph: Unified API for Microsoft 365 Data
Microsoft Graph is a single API endpoint that provides access to all Microsoft 365 data — email, calendar, files, user information, and more. Previously, you had to use separate APIs for Exchange, SharePoint, and Teams. Now Microsoft Graph provides access to all data in one place. It's like getting all information from a single information desk instead of visiting multiple stores in a mall.
Endpoint: https://graph.microsoft.com Versions: v1.0 (stable), beta (preview) Authentication: API calls using tokens obtained via MSAL Key resources: /users, /groups, /me, /messages, /calendar/events, /drive
Microsoft Graph supports both delegated and application permissions. Required permissions must be pre-registered in the app registration before making calls.
Managed Identity: Accessing Azure Services Without Credentials
Hardcoding connection passwords (connection strings, tokens, etc.) in code can lead to security incidents. Managed Identity allows Azure resources (VMs, App Service, Azure Functions, etc.) to access other Azure services without credentials. Think of an employee badge as an example. An employee enters the office building without typing a separate password — a single badge passes through all doors. The company (Azure) vouches for the employee's identity.
Two Types
| Type | Characteristics | Lifecycle | |------|----------------|-----------| | System-assigned | Automatically created when resource is created, bound to resource | Deleted when resource is deleted | | User-assigned | Created separately, can be assigned to multiple resources | Managed independently of resources |
System-assigned is dedicated to a single resource; user-assigned is suitable when multiple resources share the same identity.
!System-assigned versus user-assigned Managed Identity
With Managed Identity, you can completely remove credentials from code. DefaultAzureCredential automatically switches to developer accounts in development environments and Managed Identity in deployment environments.
Key Vault: Safely Store Secrets, Keys, and Certificates
Azure Key Vault is a service for centrally and securely managing connection strings, API keys, passwords, encryption keys, and certificates. Think of a bank vault as an example. Rather than keeping valuables at home, you entrust them to a bank vault where only authorized people can access them and all access is recorded.
Three Object Types Key Vault Manages
Secrets: Sensitive string information (connection strings, API keys, passwords) Keys: Keys used for encryption/decryption (RSA, EC keys) Certificates: TLS/SSL certificates (supports automatic renewal)
SDK Clients
| Object | SDK Client | |--------|-----------| | Secrets | SecretClient | | Keys | KeyClient | | Certificates | CertificateClient |
Exam questions frequently ask about using separate client classes for each object type.
Key Vault References (App Service/Azure Functions)
You can reference Key Vault secrets directly from app settings (Application Settings) without changing code.
Format: @Microsoft.KeyVault(SecretUri=https://myvault.vault.azure.net/secrets/mySecret/) Requires granting Key Vault access permission via Managed Identity to work When secret values change, the app automatically picks up new values
App Configuration: Centralized Configuration Management
Azure App Configuration is a service that manages configuration values for multiple applications from a single location. Think of a franchise with multiple branches. When headquarters changes menu prices, all branches automatically reflect the change. Each branch (app) does not need to carry its own price list (configuration).
Key Features
Centralization: Manage settings for multiple apps and multiple environments (dev/staging/prod) from one place Dynamic configuration: Change settings in real time without restarting apps Feature Flags: Turn specific features on and off without code deployment
Feature Flags
Feature flags are a technique where you implement features in code and control their activation/deactivation via configuration. Instead of releasing a new feature to all users at once, you can test it with 10% of users first, or apply it only to users in specific regions — enabling A/B testing.
Turn features on/off without redeploying the app Supports gradual rollout by user group Can integrate with Key Vault to manage sensitive configuration values
Exam Key Points
"Issued when you register an app with Azure AD" -- Client ID (Application ID)
"More secure than client secret for app authentication" -- Certificate
"Library for OAuth token acquisition/renewal/caching" -- MSAL
"Background service running without a user" -- Application permission
"Acting on behalf of a user" -- Delegated permission
"Unified endpoint for Microsoft 365 data" -- Microsoft Graph (https://graph.microsoft.com)
"Access Azure services from code without credentials" -- Managed Identity
"Multiple resources sharing the same identity" -- User-assigned Managed Identity
"Secret/key/certificate store, uses SecretClient" -- Azure Key Vault
"Turn features on/off without redeploying app" -- Feature Flags (App Configuration)