A company wants to implement zero-trust network access for their Azure resources and require that all service-to-service authentication uses managed identities.
Which type of managed identity should be used when multiple VMs need to share the same identity?