Microsoft Azure Data FundamentalsDescribe how to work with non-relational data on AzureHard

A company is storing a large number of images and videos in Azure Blob Storage. They want to ensure that these media files are accessible only to authorized users and applications, and that access is granted based on the principle of least privilege. Which security mechanism should be used to provide granular, role-based access control (RBAC) to specific containers and blobs?

  1. APublic access level on containers
  2. BShared Access Signatures (SAS)
  3. CAccess Keys
  4. DAzure Active Directory (AAD) integration with RBAC
Show answer & explanation

Correct answer: D. Azure Active Directory (AAD) integration with RBAC

Azure Active Directory (AAD) integration with Role-Based Access Control (RBAC) provides granular permissions for Azure Storage resources, including containers and blobs. This allows assigning specific roles with defined permissions to AAD identities (users, groups, service principals), ensuring access based on the principle of least privilege.

Why the other options are wrong

  • A. Setting a public access level on containers makes blobs publicly available, which is the opposite of ensuring authorized-only access and violates security principles.
  • B. Shared Access Signatures (SAS) provide delegated access with fine-grained control over permissions and validity, but managing many individual SAS tokens for granular RBAC across many users/apps can be complex. It's more for temporary, specific access.
  • C. Access Keys grant full access to the entire storage account, which violates the principle of least privilege and is not suitable for granular RBAC.

Azure Storage RBAC with AAD

Using Azure Active Directory and Role-Based Access Control to manage granular permissions for Azure Storage resources.

  • Assigns built-in or custom roles to AAD identities.
  • Provides granular access at storage account, container, or blob level.
  • Enforces principle of least privilege.
  • Offers centralized identity management and auditing.

Memory trick: AAD with RBAC for granular control, SAS for temporary, keys for full access.

More Describe how to work with non-relational data on Azure questions