nerdexam
Microsoft

MS-900 · Question #448

Drag and Drop Question A company is evaluating Microsoft 365 identity and access management solutions. You need to describe the differences between user- and system-assigned managed identity…

The correct answer is System-assigned; System-assigned; User-assigned. System-assigned managed identities are tied directly to a single Azure resource (e.g., a VM or App Service) and share its lifecycle - they are automatically deleted when the resource is deleted, and they cannot be shared across resources. User-assigned managed identities are…

Submitted by daniela_cl· Mar 5, 2026Describe identity, authentication, and access management capabilities of Microsoft Entra ID (Azure AD) - specifically the differences between system-assigned and user-assigned managed identities.

Question

Drag and Drop Question A company is evaluating Microsoft 365 identity and access management solutions. You need to describe the differences between user- and system-assigned managed identity solutions. Which managed identities should you describe? To answer, drag the appropriate managed identities to the correct descriptions. Each managed identity may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #448 exhibit

Answer Area

Drag items

User-assignedSystem-assigned

Correct arrangement

  • System-assigned
  • System-assigned
  • User-assigned

Explanation

System-assigned managed identities are tied directly to a single Azure resource (e.g., a VM or App Service) and share its lifecycle - they are automatically deleted when the resource is deleted, and they cannot be shared across resources. User-assigned managed identities are standalone Azure resources created independently, can be shared across multiple resources, and have their own lifecycle separate from any resource they are assigned to. The correct arrangement maps the first two descriptions (single resource lifecycle, auto-deleted with resource) to System-assigned, and the third description (shared across multiple resources, independent lifecycle) to User-assigned.

Topics

#Managed Identity#Azure Active Directory#Identity and Access Management#Microsoft 365 Security

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice