Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium
A media company uses Azure Blob Storage to store large video files. They want to prevent accidental deletion or modification of these critical files, especially by administrators who might have broad access permissions. Which Azure governance feature should they use to protect these storage accounts from unintended changes, even by users with owner roles?
- AAzure Blueprints
- BAzure Policy
- CAzure Role-Based Access Control (RBAC)
- DAzure Resource Locks
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Resource Locks
Azure Resource Locks prevent accidental deletion or modification of Azure resources, even by users with owner roles. They apply a 'CanNotDelete' or 'ReadOnly' lock to resources, subscriptions, or resource groups.
Why the other options are wrong
- A. Azure Blueprints helps standardize deployments, not protect existing resources from accidental changes.
- B. Azure Policy enforces rules and configurations but doesn't prevent accidental deletion by privileged users directly.
- C. Azure RBAC manages who can do what to resources, but an owner role can still delete resources unless a lock is applied.
Azure Resource Locks
A feature that prevents accidental deletion or modification of Azure resources, even by users with owner roles. It adds an extra layer of protection to critical resources.
- Can be applied at the subscription, resource group, or resource level.
- Two types: CanNotDelete and ReadOnly.
- Overrides RBAC permissions for deletion/modification.
Memory trick: Resource Locks are like safety chains on your most important assets.