AZ-204 Develop Azure compute solutions Practice Question
Which TWO options are valid ways to authenticate an Azure Functions app to Azure Storage when using a managed identity? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse 'managed identity' with any non-key-based method (like SAS tokens) or assume the default AzureWebJobsStorage connection string automatically uses managed identity, when in fact it defaults to a key-based connection unless explicitly configured for identity-based authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable system-assigned managed identity on the function app and grant it the 'Storage Blob Data Contributor' role
Options A and D are correct because both describe using a managed identity (system-assigned in A, user-assigned in D) to authenticate the function app to Azure Storage, which is the intended passwordless approach. In A, enabling a system-assigned managed identity on the function app and granting it the 'Storage Blob Data Contributor' role gives the identity the necessary RBAC permissions to access blob data. In D, creating a user-assigned managed identity, assigning it to the function app, and granting it the 'Storage Queue Data Contributor' role similarly provides the required RBAC permissions for queue data access. Options B and C are not valid managed-identity authentication methods because SAS tokens and storage account access keys are shared secrets, not identity-based credentials. Option E is also incorrect because the default AzureWebJobsStorage connection string typically relies on an account key or other connection-string credentials, not a managed identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable system-assigned managed identity on the function app and grant it the 'Storage Blob Data Contributor' role
Why this is correct
Enabling a system-assigned managed identity on an Azure Function App provisions an identity directly tied to the function's lifecycle. This identity, authenticated by Microsoft Entra ID, can then be granted specific Azure RBAC roles, such as 'Storage Blob Data Contributor,' allowing the function to securely access Azure Storage blobs without managing any credentials in code or configuration. This method adheres to the principle of least privilege and eliminates the security risks associated with shared secrets.
- ✗
Generate a shared access signature (SAS) token and include it in the connection string
Why it's wrong here
Generating a Shared Access Signature (SAS) token provides delegated access to Azure Storage resources for a specified period and with defined permissions. While effective for granting limited access, a SAS token is a shared secret that must be managed and rotated, and its inclusion in a connection string does not leverage Microsoft Entra ID-based managed identities. This approach requires manual credential handling, which is less secure than using managed identities.
- ✗
Use the storage account access key in the connection string
Why it's wrong here
Using a storage account access key in a connection string grants full administrative control over the entire storage account, making it a highly privileged shared secret. This method bypasses Microsoft Entra ID authentication and does not utilize managed identities, posing a significant security risk if the key is compromised. Best practices strongly advise against embedding access keys directly in application configurations due to their broad permissions and static nature.
- ✓
Create a user-assigned managed identity, assign it to the function app, and grant it the 'Storage Queue Data Contributor' role
Why this is correct
Creating a user-assigned managed identity establishes a standalone Azure resource that can be explicitly assigned to one or more Azure services, including a Function App. Once assigned, this identity can be granted specific Azure RBAC roles, such as 'Storage Queue Data Contributor,' enabling the function to authenticate to Azure Storage Queues via Microsoft Entra ID. This offers greater flexibility and reusability compared to system-assigned identities, as it can be managed independently of the consuming resource.
- ✗
Use the default AzureWebJobsStorage connection string from the function app settings
Why it's wrong here
The 'AzureWebJobsStorage' connection string is primarily used by the Azure Functions runtime for its internal operations, such as managing triggers, logging, and state. This connection string typically contains a storage account access key or a SAS token, which are shared secrets, not managed identities. Therefore, relying on this default connection string for application-specific data access does not utilize the more secure, credential-free authentication provided by managed identities.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure Queue Storage for Messaging
Key term
Key Vault Secrets
Key Vault Secrets are secure containers in Microsoft Azure that store sensitive information like passwords, connection strings, and API keys, keeping them encrypted and accessible only to authorized applications and users.
Key term
Managed identity
A managed identity is an automatically managed service principal in Azure that allows your code to authenticate to any service that supports Microsoft Entra ID authentication without storing credentials.
About these practice questions
One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.