Microsoft Azure Data FundamentalsDescribe how to work with non-relational data on AzureHard
A security auditor needs to ensure that access to sensitive documents stored in Azure Blob Storage is strictly controlled based on user roles and identities managed in Azure Active Directory (AAD). Which Azure storage management feature should be implemented to achieve this?
- APublic access blob containers
- BAccess Keys
- CAzure Active Directory (AAD) integration with Azure RBAC
- DShared Access Signatures (SAS)
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Active Directory (AAD) integration with Azure RBAC
Integrating Azure Blob Storage with Azure Active Directory (AAD) and using Azure Role-Based Access Control (RBAC) allows for fine-grained access control to blob data based on AAD identities and roles, ensuring that only authorized users can access sensitive documents.
Why the other options are wrong
- A. Public access blob containers make data publicly available and are entirely unsuitable for sensitive documents.
- B. Access Keys provide full access to the storage account and are not suitable for fine-grained, role-based control.
- D. SAS tokens provide delegated access but are not tied to AAD user roles directly and can be complex to manage at scale.
Azure Storage RBAC with AAD
A security feature that combines Azure Active Directory identities with Azure Role-Based Access Control to provide fine-grained permissions for accessing data in Azure Storage accounts.
- Allows assigning specific roles (e.g., 'Storage Blob Data Contributor') to AAD users or groups.
- Provides identity-based authentication and authorization.
- Offers a more secure and manageable alternative to shared access keys for production environments.
Memory trick: AAD and RBAC are the gatekeepers of blobs.