A service running on VM1 needs to manage the resources in resource group RG1 using VM1's identity. What should you do first in the Azure portal?
Choose an answer
Tap an option to check your answer.
Correct answer: From the Azure portal, modify the Managed Identity settings of VM1.
Why this is the answer
The first step is to enable a system-assigned managed identity for VM1. This creates an identity in Azure Active Directory (AAD) that VM1 can use to authenticate to Azure services. Without this identity, VM1 cannot be granted permissions. After enabling the managed identity on VM1, you would then navigate to RG1's Access control (IAM) settings to assign the necessary role to VM1's managed identity, allowing it to manage resources within RG1. Modifying Access control (IAM) settings of VM1 would be for granting other identities access to VM1 itself, not for VM1 to access other resources. Modifying Policies settings of RG1 enforces rules on resource creation and updates, which is unrelated to VM1's identity accessing resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed