A tamarack inventory daemon on App Service keeps failing when its Entra app-registration client secret expires. How should the developer remove that secret-rotation hop?
Select an answer to reveal the explanation.
Short Explanation
Client secrets expire and page people at 2 a.m. Managed identity on App Service is Azure’s badge—no secret to rotate on that hop. Keep secrets out of the browser and out of Insights.
Full Explanation
App-registration client secrets require rotation and create outage risk when they expire. Enabling a managed identity on App Service lets the host obtain tokens for Azure resources without storing a client secret. Embedding secrets in front-end bundles, logging them to Application Insights, or hard-coding them on a desktop host are insecure or out-of-scope alternatives.