A web app hosted on Azure App Service calls a model deployment by using an API key stored in app settings. Security requirements state that the app must authenticate without any stored secret and must hold only the permissions needed to run inference. Which two actions should you perform? (Select all that apply)