Azure AI services accept two kinds of credentials. Keys are simple: every resource has two, and anyone who holds one can call the resource. That simplicity is also the risk, because a key copied into code, a config file or a chat message works for whoever finds it, and the logs cannot tell you which person or app used it. Microsoft Entra ID (formerly Azure Active Directory) authentication replaces the shared secret with a token issued to a specific identity, and access is controlled with Azure role-based access control (RBAC).
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.