A developer is building a new application that will store images in Azure Blob Storage. The application needs to generate shared access signatures (SAS) for temporary, time-limited access to specific blobs for users. You need to recommend the most secure and granular method for generating these SAS tokens.
- AStored Access Policy SAS
- BAccount SAS
- CService SAS
- DUser Delegation SAS
Show answer & explanationAnswer & explanation
Correct answer: D. User Delegation SAS
User Delegation SAS is the most secure and granular method for generating SAS tokens because it is secured with Azure Active Directory (Azure AD) credentials, rather than the storage account key. This eliminates the need to distribute or manage storage account keys, reducing the risk of key compromise and allowing for more specific permissions based on the user's Azure AD identity.
Why the other options are wrong
- A. Stored Access Policy SAS defines permissions on a container or share, which can then be referenced by a Service SAS. While it centralizes policy management, the underlying SAS is still secured by the storage account key.
- B. Account SAS grants broad permissions across all storage services in an account and is secured with the storage account key, making it less granular and more risky.
- C. Service SAS grants access to a specific service (e.g., Blob) but is still secured with the storage account key, offering less security than User Delegation SAS.
User Delegation SAS
A User Delegation SAS is a Shared Access Signature (SAS) secured with Azure Active Directory (Azure AD) credentials, allowing for more granular control and enhanced security by integrating with Azure RBAC and eliminating the need to use storage account keys.
- Secured with Azure AD credentials.
- Requires Azure RBAC permissions to create and use.
- Offers superior security compared to Account SAS or Service SAS.
- Supports blob and container operations, but not queues or tables directly.
- Tokens are generated for a specific user identity.
Memory trick: SAS tokens: Account for broad, Service for specific, User for secure identity, Stored for central policy.