Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A global manufacturing company uses Azure Data Factory to ingest and transform sensitive customer data from various on-premises and cloud sources. The transformed data is stored in Azure Data Lake Storage Gen2. The company needs to enforce strict access controls based on user roles and data classifications, ensuring that only authorized personnel can access specific data sets, even at the file or folder level within the Data Lake. Which security mechanism should be primarily used to achieve this granular access control?
- AShared Access Signatures (SAS)
- BAzure Active Directory (Azure AD) and Access Control Lists (ACLs)
- CAzure Policy
- DStorage Account Access Keys
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Active Directory (Azure AD) and Access Control Lists (ACLs)
Azure Data Lake Storage Gen2 integrates with Azure AD for identity management and supports POSIX-like Access Control Lists (ACLs) to provide granular, file-level and folder-level permissions, which is essential for enforcing access based on user roles and data classifications.
Why the other options are wrong
- A. SAS tokens provide time-limited, delegated access but are not ideal for persistent, role-based granular access control.
- C. Azure Policy is used for enforcing organizational standards and assessing compliance, not for direct data access control.
- D. Storage Account Access Keys grant full access to the entire storage account and are not suitable for granular, role-based access control.
Azure Data Lake Storage Gen2 ACLs
Access Control Lists (ACLs) for Azure Data Lake Storage Gen2 provide granular, POSIX-like permissions at the file and directory level, integrated with Azure Active Directory for identity management.
- Granular permissions for files and directories.
- Integrated with Azure Active Directory identities.
- Supports both owner and named user/group permissions.
Memory trick: ACLs are like bouncers for each file, checking your Azure AD ID.