Match each blob access method or setting to its best use case.
Drag a concept onto its matching description — or click a concept then click the description.
Provides full access to the storage account and should be protected carefully.
Grants time-limited access to specific resources and permissions.
Authorizes users or applications through Microsoft Entra ID at a chosen scope.
Allows anonymous read access when enabled for the container.
Lets an Azure-hosted app authenticate without storing credentials or secrets.
Why these pairings
Public endpoint with anonymous access is for public content. Private endpoint with managed identity provides secure VM access. SAS tokens grant time-limited restricted access.
Azure AD with RBAC centralizes identity management. Storage account key gives full admin control. Immutable storage with legal hold ensures data cannot be altered or deleted.