Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard

A developer is implementing role-based access control (RBAC) for an Azure Storage Account. A new custom role needs to be created that allows a specific Azure Function App to read and list blobs, but not write or delete them. Which `actions` property should be included in the custom role definition?

  1. A`Microsoft.Storage/storageAccounts/read`, `Microsoft.Storage/storageAccounts/write`
  2. B`Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write`, `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete`
  3. C`Microsoft.Storage/storageAccounts/blobServices/containers/blobs/*`
  4. D`Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read`, `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/list`
Show answer & explanation

Correct answer: D. `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read`, `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/list`

The problem specifies that the custom role should allow reading and listing blobs, but not writing or deleting. Option B correctly includes the `read` and `list` actions for blobs, adhering to the principle of least privilege. Option A includes write/delete, Option C is for storage accounts themselves, not blobs, and Option D grants all permissions.

Why the other options are wrong

  • A. These actions apply at the storage account level, not specifically for blob operations, and include write permissions.
  • B. These actions grant write and delete permissions, which are explicitly forbidden by the requirement.
  • C. The wildcard `*` grants all possible actions on blobs, violating the principle of least privilege and the explicit restriction on write/delete.

Azure RBAC Custom Role Definition

A JSON definition that specifies a set of permissions (actions, notActions, dataActions, notDataActions) that can be assigned to an Azure principal (user, group, managed identity, service principal).

  • Allows fine-grained control over Azure resources
  • Adheres to the principle of least privilege
  • Can define both control plane and data plane actions

Memory trick: RBAC Custom Role: Only give the key for *what* they need to *do*.

More Implement Azure security questions