Microsoft Azure Data FundamentalsDescribe how to work with non-relational data on AzureHard
A large enterprise stores sensitive customer data in Azure Blob Storage. They need to implement a robust access control mechanism that integrates with their existing Azure Active Directory (AAD) identity system. Access should be granted based on job roles and responsibilities, rather than managing shared access signatures (SAS) or account keys for individual users. Which Azure security feature should be used to achieve this?
- AAzure Role-Based Access Control (RBAC)
- BAzure Firewall
- CStorage Account Access Keys
- DShared Access Signatures (SAS)
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Role-Based Access Control (RBAC)
Azure Role-Based Access Control (RBAC) allows you to manage who has access to Azure resources, what they can do with those resources, and what areas they have access to. By assigning AAD identities (users, groups, service principals) to specific RBAC roles on Blob Storage, the enterprise can enforce access based on job roles and responsibilities.
Why the other options are wrong
- B. Azure Firewall is a network security service that controls inbound and outbound traffic, not an identity-based access control mechanism for storage resources.
- C. Storage Account Access Keys grant full control to the entire storage account and are not suitable for fine-grained, role-based access control for individual users.
- D. Shared Access Signatures (SAS) provide delegated access with specific permissions and expiry, but managing them for many individual users and roles is complex and not integrated with AAD roles.
Azure Role-Based Access Control (RBAC) for Storage
A system that provides fine-grained access management to Azure resources, including Storage accounts, by assigning roles to Azure Active Directory identities (users, groups, service principals).
- Integrates directly with Azure Active Directory (AAD).
- Grants permissions based on predefined or custom roles.
- Enforces the principle of least privilege.
- Allows managing access at the subscription, resource group, or individual resource level.
Memory trick: RBAC is like a 'bouncer' at a club, checking your role before you enter.