QuestionQ59

Implement Azure security

You develop and deploy an Azure Logic app that invokes an Azure Function app. The Azure Function app contains an OpenAPI (Swagger) definition and uses an Azure Blob storage account. All resources are secured by using Azure Active Directory (Azure AD).

The Azure Logic app must securely access the Azure Blob storage account. Azure AD resources must remain if the Azure Logic app is deleted.

You need to secure the Azure Logic app.

What should you do?

Explanation

A user-assigned managed identity is independent of the Logic App resource lifecycle, so deleting the Logic App does not automatically delete the identity in Microsoft Entra ID. Assigning the identity an appropriate Azure RBAC role on the Blob storage account grants secure, credential-free access to the storage resource.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!