AZ-104 Implement and Manage Storage Practice Question
Which two authentication methods let an app access blob data without storing the storage account key on the machine? Select two.
⚠ Common exam trap
A common mix-up: candidates confuse a service SAS (which still requires the account key) with a user delegation SAS (which does not), or they mistakenly think that anonymous access is a valid authentication method for an app.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID authorization with an appropriate Azure RBAC role.
Microsoft Entra ID authorization with an appropriate Azure RBAC role (e.g., Storage Blob Data Contributor) allows an app to authenticate to blob storage using OAuth 2.0 tokens, eliminating the need to store the storage account key on the machine. Option B is correct because a user delegation SAS is signed with Microsoft Entra ID credentials and can be generated without the account key, providing time-limited, scoped access to blob data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID authorization with an appropriate Azure RBAC role.
Why this is correct
This method is correct because Microsoft Entra ID integrates with Azure RBAC to grant granular permissions for blob data. The app authenticates via OAuth 2.0, obtains a token for a user, group, service principal, or managed identity, and then that token is used to enforce role assignments like Storage Blob Data Reader or Contributor. This eliminates the need to store or rotate shared secrets, and it automatically supports conditional access, auditing, and centralized identity management.
- ✓
A user delegation SAS generated through Microsoft Entra ID.
Why this is correct
This method is also correct because a user delegation SAS is signed with Microsoft Entra ID credentials rather than the storage account's shared key. The app first authenticates to Entra ID, then requests a SAS token scoped to a specific container or blob, with its own expiry and permissions. This provides time-limited, fine-grained access without ever exposing the account key to the application, making it a secure alternative for delegating blob access.
- ✗
The storage account access key.
Why it's wrong here
This method is wrong because the account key is a long-lived shared secret that grants full administrative access to the entire storage account, including all blobs, queues, tables, and file shares. Storing the key in an app's configuration or environment introduces a major security risk: if leaked, an attacker gains unrestricted control, and rotating the key forces application updates. It also bypasses identity-based security and does not support fine-grained permissions or per-user auditing.
When this WOULD be correct
This option would be correct in a question that asks for a method to authenticate access to blob data when the application can securely store the key (e.g., in Azure Key Vault) or when the question does not prohibit storing the key on the machine.
- ✗
A service SAS generated directly from the account key.
Why it's wrong here
This method is wrong because a service SAS is signed using the storage account's shared key, meaning the key is still required to generate or validate the token. Although the SAS limits access to specific services and resources, the application or the service that generates it must protect the account key somewhere, which defeats the goal of eliminating secret management. It also lacks the identity-based audit trail and conditional access policies that Entra ID authorization provides.
When this WOULD be correct
If the question asked 'Which method allows an app to access blob data with time-limited access and without storing the account key on the machine, but the app can retrieve the key from a secure vault at runtime?' then a service SAS generated from the account key (retrieved from a vault) would be correct.
- ✗
Anonymous public access to the container.
Why it's wrong here
This method is wrong because anonymous public access allows any unauthenticated client on the internet to read blob data without any proof of identity. It completely bypasses Entra ID, RBAC, and SAS-based security mechanisms, exposing potentially sensitive data to anyone who discovers the container's URL. This is unacceptable for a secure application that requires controlled, role-based access, and Azure recommends disabling anonymous access for all storage accounts unless explicitly required for public data.
When this WOULD be correct
If the question were 'Which method allows public read access to blob data without requiring authentication?' then anonymous public access would be correct, as it enables unauthenticated access to containers configured for public access.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Entra ID authorization with an appropriate Azure RBAC role.Correct answer▾
Why this is correct
This method is correct because Microsoft Entra ID integrates with Azure RBAC to grant granular permissions for blob data. The app authenticates via OAuth 2.0, obtains a token for a user, group, service principal, or managed identity, and then that token is used to enforce role assignments like Storage Blob Data Reader or Contributor. This eliminates the need to store or rotate shared secrets, and it automatically supports conditional access, auditing, and centralized identity management.
✗The storage account access key.Wrong answer — click to see why▾
Why this is wrong here
The storage account access key provides full control over the storage account, but it must be stored on the machine to authenticate requests, which violates the requirement of not storing the key on the machine.
★ When this WOULD be the correct answer
This option would be correct in a question that asks for a method to authenticate access to blob data when the application can securely store the key (e.g., in Azure Key Vault) or when the question does not prohibit storing the key on the machine.
Why candidates choose this
Candidates often default to using access keys because they are familiar and simple, overlooking the explicit constraint in the question about not storing the key on the machine.
✗A service SAS generated directly from the account key.Wrong answer — click to see why▾
Why this is wrong here
A service SAS generated from the account key still requires the storage account key to create it, and the key is stored on the machine or in the code, violating the constraint of not storing the key.
★ When this WOULD be the correct answer
If the question asked 'Which method allows an app to access blob data with time-limited access and without storing the account key on the machine, but the app can retrieve the key from a secure vault at runtime?' then a service SAS generated from the account key (retrieved from a vault) would be correct.
Why candidates choose this
Candidates may think a SAS token itself does not expose the account key, so it avoids storing the key, but they overlook that generating a service SAS requires the account key to be present at creation time.
✗Anonymous public access to the container.Wrong answer — click to see why▾
Why this is wrong here
Anonymous public access allows anyone to read blob data without authentication, but it does not involve any authentication method for an app; the app would simply access the data without storing a key, but the question requires an authentication method, not the absence of one.
★ When this WOULD be the correct answer
If the question were 'Which method allows public read access to blob data without requiring authentication?' then anonymous public access would be correct, as it enables unauthenticated access to containers configured for public access.
Why candidates choose this
Candidates may think anonymous access avoids storing keys, but they overlook that the question asks for authentication methods; anonymous access is not an authentication method but a permission setting that bypasses authentication entirely.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
Blob
A blob is a large piece of unstructured data, like a photo or video, stored in the cloud with a unique identifier.
Key term
RBAC
RBAC is a method of restricting network access based on the roles of individual users within an organization, where permissions are assigned to roles rather than to individuals directly.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.