AZ-204 Practice Question: Connect to and consume Azure services and third-party services
A developer is building a .NET console application that needs to read and write files in an Azure Storage account. The application will run on a developer's workstation and must authenticate using Microsoft Entra ID (Azure AD). The developer has been granted the Storage Blob Data Contributor role on the storage account. Which method should the developer use to authenticate the application to Azure Storage?
⚠ Common exam trap
The trap here is assuming that a SAS token or account key is acceptable because it works, but the requirement specifically mandates Microsoft Entra ID authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the DefaultAzureCredential class from the Azure.Identity library.
DefaultAzureCredential simplifies authentication by trying several methods in order, including environment variables, managed identity, and developer tool credentials. On a workstation, it will use the signed-in user's Microsoft Entra ID identity from Azure CLI or Visual Studio. Because the developer has the Storage Blob Data Contributor role, this credential will have the necessary permissions to read and write blobs, satisfying the Microsoft Entra ID requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the storage account's connection string with the account name and key.
Why it's wrong here
A connection string with the account name and key uses shared key authorization, not Microsoft Entra ID. This method grants full access to the storage account and does not respect the Storage Blob Data Contributor role. It is not the correct approach when Microsoft Entra ID authentication is required. The developer should avoid using account keys and instead use Microsoft Entra ID credentials.
- ✓
Use the DefaultAzureCredential class from the Azure.Identity library.
Why this is correct
DefaultAzureCredential automatically attempts multiple authentication methods, including Azure CLI credentials, managed identity, and Visual Studio account. On a developer workstation, it can use the developer's Microsoft Entra ID login from tools like Azure CLI or Visual Studio. Since the developer has the Storage Blob Data Contributor role, this credential will authenticate successfully and is the recommended approach for Microsoft Entra ID authentication.
- ✗
Use the storage account's primary access key in the connection string.
Why it's wrong here
Using the primary access key provides full access to the storage account and bypasses Microsoft Entra ID authentication. While it works, it does not meet the requirement to authenticate using Microsoft Entra ID. Additionally, access keys are sensitive and should not be used when Microsoft Entra ID authentication is available. The developer should leverage the assigned role for better security and management.
- ✗
Generate a shared access signature (SAS) token with read and write permissions.
Why it's wrong here
A SAS token is a delegated access method that grants specific permissions without requiring Microsoft Entra ID. However, the scenario explicitly requires Microsoft Entra ID authentication. While a SAS token can be used, it does not fulfill the requirement and may be less secure if not managed properly. The developer should use Microsoft Entra ID to align with the role assignment and security best practices.
Go deeper
Related to this question
Learn chapter
Application Insights
Key term
Key Vault Secrets
Key Vault Secrets are secure containers in Microsoft Azure that store sensitive information like passwords, connection strings, and API keys, keeping them encrypted and accessible only to authorized applications and users.
Key term
Managed identity
A managed identity is an automatically managed service principal in Azure that allows your code to authenticate to any service that supports Microsoft Entra ID authentication without storing credentials.
About these practice questions
This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.