Microsoft Azure Data FundamentalsDescribe how to work with non-relational data on AzureHard

A security auditor needs to ensure that access to sensitive documents stored in Azure Blob Storage is managed using fine-grained permissions based on user roles within Azure Active Directory. Which Azure management task is most appropriate for implementing this requirement?

  1. AImplementing Azure Role-Based Access Control (RBAC) with Azure AD integration
  2. BSetting up Storage Account Access Keys for each application
  3. CConfiguring Shared Access Signatures (SAS) for each user
  4. DApplying Access Control Lists (ACLs) directly to blob containers
Show answer & explanation

Correct answer: A. Implementing Azure Role-Based Access Control (RBAC) with Azure AD integration

Azure RBAC, integrated with Azure Active Directory, allows for fine-grained, role-based permissions to Azure resources, including Blob Storage. This enables assigning specific roles (e.g., 'Storage Blob Data Reader') to users or groups, ensuring access is managed centrally and securely based on identity.

Why the other options are wrong

  • B. Storage Account Access Keys grant full control over the storage account and should be avoided for individual user access due to their broad permissions and security risks.
  • C. SAS tokens grant limited, time-bound access, but managing them for individual users and their roles is complex and not suitable for fine-grained, centralized access control.
  • D. ACLs are typically used in file systems like Data Lake Storage Gen2 for granular control, but for Blob Storage, RBAC with Azure AD is the more modern and integrated approach for user/role-based permissions.

Azure RBAC for Storage

Azure Role-Based Access Control (RBAC) for Storage allows for managing access permissions to Azure Storage resources (like Blob Storage) using Azure Active Directory identities, assigning specific roles with defined permissions.

  • Integrates with Azure Active Directory for identity management.
  • Provides fine-grained access control at the resource group, storage account, or container level.
  • Uses built-in roles (e.g., Storage Blob Data Reader, Contributor) or custom roles.
  • Recommended for secure, centralized access management.

Memory trick: Storage Access: Keys are broad, SAS is temporary, RBAC is role-based.

More Describe how to work with non-relational data on Azure questions