Courseiva
Implement and Manage StoragemediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Storage Practice Question

A developer can access an Azure Blob container from the portal using Microsoft Entra sign-in, but their custom app gets a 403 error when reading the same blob. The storage account is configured to use Azure AD authorization. What is the most likely fix?

⚠ Common exam trap

Test-takers frequently confuse the management plane Reader role (which allows viewing the storage account in the portal) with the data plane Storage Blob Data Reader role (which is required to actually read blob content), leading them to incorrectly select Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assign the user the Storage Blob Data Reader role on the container or storage account.

The developer can authenticate via the portal because the portal uses the user's own Microsoft Entra identity, which may have implicit permissions (e.g., via group membership or subscription-level Reader). However, the custom app must explicitly be granted the Storage Blob Data Reader role on the container or storage account to authorize data plane operations (reading blobs). Without this role assignment, the app's identity lacks the RBAC permission to perform blob read operations, resulting in a 403 error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assign the user the Storage Blob Data Reader role on the container or storage account.

    Why this is correct

    A 403 in this scenario usually means the identity lacks data-plane permissions. The user needs an Azure RBAC role such as Storage Blob Data Reader at the appropriate scope so the app can read blob content through Azure AD authorization.

  • Assign the user the Reader role on the subscription.

    Why it's wrong here

    The Reader role on the subscription provides management-plane visibility, enabling the user to see storage accounts and their properties via ARM, but it does not grant any data-plane permissions on blob containers. Azure Storage enforces a strict separation between control plane (management) and data plane (data access), and blob reads are authorized by data-plane roles such as Storage Blob Data Reader. The user's Azure AD token would still be rejected by the blob endpoint because the Reader role lacks the Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read action required to read blob content.

    When this WOULD be correct

    This option would be correct in a scenario where the question asks: 'A user can see the storage account in the portal but cannot view its configuration settings. What role should be assigned?' The Reader role on the subscription provides read-only access to Azure resources, enabling the user to view storage account properties.

  • Enable shared key access so the app can bypass Azure AD permissions.

    Why it's wrong here

    Enabling shared key access would allow requests to be authenticated with the storage account key, but it does not grant the user's Azure AD identity any data-plane permissions. It changes the authentication mechanism from Azure AD to key-based, and because shared key access is a tenant-wide setting, it would expose the entire storage account to anyone with the key—rather than selectively granting this user read access to blobs. This weakens security and does not address the 403, which stems from a missing RBAC data role.

    When this WOULD be correct

    This option would be correct if the question stated that the storage account requires shared key access for legacy applications that cannot use Azure AD, and the developer's app needs to access blobs without Azure AD integration.

  • Move the container to the Hot tier so Azure AD authentication can succeed.

    Why it's wrong here

    Changing the container's access tier to Hot does not affect authentication or authorization in any way. The Hot, Cool, and Archive tiers are designed to manage storage costs and retrieval latency, not to control which identities can access data. If the user does not have a data-plane role assignment, Azure AD authorization will fail identically in the Hot tier, so the 403 would persist. The only effective fix is to assign the appropriate RBAC data role, such as Storage Blob Data Reader.

    When this WOULD be correct

    A question where a blob storage container is in the Cool or Archive tier and an application needs to read blobs, but the app fails because the container is offline (Archive) or has higher latency. Moving to Hot would resolve access latency or restore online status.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Assign the user the Storage Blob Data Reader role on the container or storage account.Correct answer

Why this is correct

A 403 in this scenario usually means the identity lacks data-plane permissions. The user needs an Azure RBAC role such as Storage Blob Data Reader at the appropriate scope so the app can read blob content through Azure AD authorization.

Assign the user the Reader role on the subscription.Wrong answer — click to see why

Why this is wrong here

The Reader role on the subscription grants read access to Azure Resource Manager resources (e.g., VM, storage account metadata) but does not grant data-level permissions to blob containers. The 403 error occurs because the app lacks data-plane authorization, which requires a role like Storage Blob Data Reader.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the question asks: 'A user can see the storage account in the portal but cannot view its configuration settings. What role should be assigned?' The Reader role on the subscription provides read-only access to Azure resources, enabling the user to view storage account properties.

Why candidates choose this

Candidates may confuse Azure RBAC roles with Azure AD data-plane roles, assuming that any 'Reader' role grants access to data. They might also think subscription-level access cascades to all data, which is incorrect for Azure Storage.

Enable shared key access so the app can bypass Azure AD permissions.Wrong answer — click to see why

Why this is wrong here

Enabling shared key access would allow the app to bypass Azure AD authorization, but the storage account is configured to use Azure AD authorization, and the issue is that the app is not using Azure AD tokens. The correct fix is to assign the appropriate RBAC role, not to enable a less secure authentication method.

★ When this WOULD be the correct answer

This option would be correct if the question stated that the storage account requires shared key access for legacy applications that cannot use Azure AD, and the developer's app needs to access blobs without Azure AD integration.

Why candidates choose this

Candidates may think enabling shared key access is a quick workaround to bypass permission errors, without understanding that Azure AD authorization is the intended and more secure method, and that the real issue is missing role assignment.

Move the container to the Hot tier so Azure AD authentication can succeed.Wrong answer — click to see why

Why this is wrong here

Moving a container to the Hot tier does not affect Azure AD authentication; tier changes impact cost and performance, not authorization. The 403 error is due to missing RBAC role assignment, not storage tier.

★ When this WOULD be the correct answer

A question where a blob storage container is in the Cool or Archive tier and an application needs to read blobs, but the app fails because the container is offline (Archive) or has higher latency. Moving to Hot would resolve access latency or restore online status.

Why candidates choose this

Candidates may confuse storage tier properties with authentication mechanisms, thinking that certain tiers restrict Azure AD access, or they may recall that Archive tier blobs must be rehydrated before reading, leading them to incorrectly assume a tier change fixes authorization errors.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.