You have an Azure subscription that contains an Azure Automation account named Automation1 and an Azure key vault named Vault1. Vault1 contains a secret named Secret 1. You enable a system-assigned managed identity for Automation1. You need to ensure that Automation! can read the contents of Secret1. The solution must meet the following requirements: * Prevent Automation1 from accessing other secrets stored in Vault1. * Follow the principle of least privilege. What should you do?