Your company stores sensitive documents in an Azure Storage account. You need to ensure that only authorized Microsoft Entra ID users can read the documents, and that shared keys (account access keys) cannot be used. Which two steps must you take? (Choose the most appropriate single answer that describes the combined action.)
Trap 1: Enable Microsoft Entra ID authentication and use SAS tokens with a…
Microsoft Entra ID authentication is enabled, but SAS tokens with a stored access policy still rely on account keys, violating the requirement to disable shared keys.
Trap 2: Enable firewall and virtual network service endpoints, then assign…
Firewalls and virtual network service endpoints control network access but do not restrict authentication methods; shared keys could still be used.
Trap 3: Use user-delegation SAS tokens and disable shared key access
User-delegation SAS tokens are signed with Microsoft Entra ID credentials, but they can be used by anyone possessing the token, not only authorized Entra ID users. Additionally, disabling shared key access alone does not enforce Entra ID authentication; RBAC roles are still needed.
- A
Disable shared key access and configure RBAC roles for Microsoft Entra ID users
Ly disables shared key access and configures RBAC roles, ensuring only authorized Microsoft Entra ID users can read documents.
- B
Enable Microsoft Entra ID authentication and use SAS tokens with a stored access policy
Why it fails: Microsoft Entra ID authentication is enabled, but SAS tokens with a stored access policy still rely on account keys, violating the requirement to disable shared keys.
- C
Enable firewall and virtual network service endpoints, then assign RBAC roles
Why it fails: Firewalls and virtual network service endpoints control network access but do not restrict authentication methods; shared keys could still be used.
- D
Use user-delegation SAS tokens and disable shared key access
Why it fails: User-delegation SAS tokens are signed with Microsoft Entra ID credentials, but they can be used by anyone possessing the token, not only authorized Entra ID users. Additionally, disabling shared key access alone does not enforce Entra ID authentication; RBAC roles are still needed.