Microsoft Azure Data FundamentalsDescribe how to work with non-relational data on AzureMedium

A security auditor needs to ensure that access to sensitive documents stored in Azure Blob Storage is granted only to specific users and groups within Azure Active Directory (AAD). The auditor requires a solution that provides fine-grained control over individual blobs and containers, leveraging existing AAD identities. Which mechanism should be used?

  1. AAzure Role-Based Access Control (RBAC)
  2. BIP Firewall Rules
  3. CAccess Keys for Storage Accounts
  4. DShared Access Signatures (SAS)
Show answer & explanation

Correct answer: A. Azure Role-Based Access Control (RBAC)

Azure Role-Based Access Control (RBAC) allows fine-grained access management for Azure resources, including Blob Storage, by assigning roles to AAD users or groups. This aligns with the requirement to leverage existing AAD identities and provide precise control over resources.

Why the other options are wrong

  • B. IP Firewall Rules restrict access based on IP addresses, but do not authenticate users or provide identity-based access control.
  • C. Access Keys grant full access to the entire storage account and are not suitable for fine-grained control or using AAD identities.
  • D. Shared Access Signatures (SAS) provide delegated access with limited permissions and duration, but are not ideal for managing persistent access for AAD users/groups.

Azure Role-Based Access Control (RBAC) for Storage

A system that provides fine-grained access management to Azure resources, including storage accounts, by assigning roles to Azure Active Directory identities.

  • Integrates with Azure Active Directory.
  • Grants specific permissions to users, groups, service principals.
  • Provides granular control over resources like blobs and containers.

Memory trick: RBAC is the key to roles for AAD users.

More Describe how to work with non-relational data on Azure questions