An on-premises Server1 hosts an ASP.NET app App1 under IIS. You plan to containerize App1 and deploy it to Azure App Service; the container image will be stored in an Azure Container Registry named ACR1. Using Azure Migrate's App Containerization tool, you must grant the tool the minimum necessary privilege to push the image to ACR1. Which credential type should the tool use?
Choose an answer
Tap an option to check your answer.
Correct answer: a Microsoft Entra service principal.
Why this is the answer
A Microsoft Entra service principal is the correct choice because it provides a secure and automated way for applications, services, and automation tools (like Azure Migrate's App Containerization) to access Azure resources. You can assign specific, least-privilege roles to the service principal on ACR1, ensuring the tool only has permission to push images without granting broader administrative access. Using the admin user account of ACR1 is not recommended as it grants full administrative control, violating the principle of least privilege. A managed identity is typically used for Azure resources to authenticate to other Azure services, not for an on-premises tool like Azure Migrate's App Containerization. A Microsoft Entra user account is for human users and is not suitable for automated, programmatic access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed