Microsoft Certified: Azure Administrator AssociateImplement and manage storageHard
A developer is writing code to interact with Azure Blob Storage. They need to retrieve a list of all blobs within a specific container that were last modified more than 30 days ago. Which method of authentication should the developer use for their application to ensure secure and granular access, following the principle of least privilege?
- AAnonymous public read access
- BShared Access Signature (SAS)
- CShared Key authentication
- DAzure Active Directory (Azure AD) authentication
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Active Directory (Azure AD) authentication
Azure Active Directory (Azure AD) authentication allows for granular, role-based access control (RBAC) to Azure storage resources. This aligns with the principle of least privilege, as the application can be granted only the necessary permissions (e.g., 'Storage Blob Data Reader') without exposing shared keys or SAS tokens.
Why the other options are wrong
- A. Anonymous public read access grants access to anyone, violating security best practices and the principle of least privilege.
- B. SAS tokens provide granular access but require careful management (expiration, revocation) and can be over-privileged if not carefully constructed. Azure AD is generally preferred for application-level authentication.
- C. Shared Key authentication grants full access to the storage account, violating the principle of least privilege.
Azure AD Authentication for Storage
Azure Active Directory (Azure AD) authentication uses Azure role-based access control (RBAC) to grant granular permissions to security principals (users, groups, applications) for accessing Azure storage resources.
- Provides secure, token-based authentication.
- Enables granular access control with RBAC.
- Supports managed identities for Azure resources.
- Adheres to the principle of least privilege.
Memory trick: Keys, SAS, AD: Choose Your Access Path Wisely.