Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A company is developing an Azure Function App that needs to interact with an Azure Storage Account to read and write blobs. The security team has mandated that the Function App must use a managed identity for authentication to the Storage Account and that access should be restricted to specific blob containers. Which Azure RBAC role, scoped to the specific blob container, should be assigned to the Azure Function App's managed identity to provide the necessary permissions while adhering to the principle of least privilege?
- AStorage Blob Data Owner
- BReader
- CStorage Blob Data Contributor
- DStorage Account Contributor
Show answer & explanationAnswer & explanation
Correct answer: C. Storage Blob Data Contributor
The 'Storage Blob Data Contributor' role allows for reading, writing, and deleting blobs within a container. Scoping this role to the specific blob container ensures the Function App has the necessary read/write permissions for blobs while adhering to the principle of least privilege, as it doesn't grant broader access to the entire storage account or management plane.
Why the other options are wrong
- A. The 'Storage Blob Data Owner' role grants full control, including managing access, which is more than just reading/writing blobs and violates least privilege.
- B. The 'Reader' role only allows reading data, not writing, which is insufficient for the Function App's requirement to read *and write* blobs.
- D. The 'Storage Account Contributor' role grants management access to the entire storage account, not just data access to blobs, and is too broad.
Azure Storage Blob Data Roles
Azure RBAC roles specifically for controlling data plane access to Azure Blob Storage, allowing granular permissions like reading, writing, or deleting blobs.
- Storage Blob Data Owner: Full control over blob data, including access management.
- Storage Blob Data Contributor: Read, write, and delete blob data.
- Storage Blob Data Reader: Read blob data only.
- Can be scoped to container or storage account level.
Memory trick: To read and write blobs, the Function needs the 'Blob Data Contributor' role.