Microsoft Azure Data FundamentalsDescribe how to work with non-relational data on AzureHard

A retail company uses Azure Blob Storage to store millions of customer receipts as PDF files. They need to implement a solution that provides specific permissions to different departments, ensuring that the marketing department can only read receipts, while the finance department can read and delete receipts. Access should be managed using Azure Active Directory identities. Which Azure management task is most appropriate for this scenario?

  1. AUsing Azure Storage Access Keys
  2. BSetting up Access Control Lists (ACLs) on containers
  3. CImplementing Azure Role-Based Access Control (RBAC)
  4. DConfiguring Shared Access Signatures (SAS)
Show answer & explanation

Correct answer: C. Implementing Azure Role-Based Access Control (RBAC)

Azure Role-Based Access Control (RBAC) with Azure Active Directory (AAD) is the most appropriate solution. RBAC allows granular permissions to be assigned to AAD identities (users, groups, service principals) at various scopes (subscription, resource group, individual resource), defining exactly what actions they can perform (e.g., 'Reader' for marketing, 'Storage Blob Data Contributor' for finance) on specific Blob Storage resources.

Why the other options are wrong

  • A. Azure Storage Access Keys provide full control over the storage account and are not suitable for granular, departmental access control based on the principle of least privilege with AAD identities.
  • B. Access Control Lists (ACLs) are primarily used with Azure Data Lake Storage Gen2 for hierarchical namespace permissions, not the primary method for Blob Storage departmental access with AAD identities.
  • D. Shared Access Signatures (SAS) provide delegated access with fine-grained control but are typically used for programmatic access or temporary, time-limited access, not for managing standing departmental permissions with AAD identities.

Azure RBAC for Storage

Azure Role-Based Access Control (RBAC) for Storage allows you to manage access to Azure storage accounts using Azure Active Directory (AAD) identities. It provides granular permissions on storage resources (containers, blobs) based on assigned roles.

  • Integrates with Azure Active Directory (AAD) for identity management.
  • Provides granular control over data access (read, write, delete, etc.).
  • Follows the principle of least privilege by assigning only necessary permissions.
  • Roles can be assigned at various scopes: subscription, resource group, storage account, container, or blob.

Memory trick: Think 'RBAC: Roles Based on AAD, Controls Access to Cloud Data'.

More Describe how to work with non-relational data on Azure questions