Your organization uses Azure Storage accounts with blob containers. You need to ensure that only authorized applications can access the storage account, without using shared keys or shared access signatures. What should you configure?
Azure AD authentication with managed identities assigns an automatically managed service principal to the compute resource, and the SDK obtains an OAuth 2.0 token from Azure Instance Metadata Service without storing any secrets. The identity is then mapped to Azure RBAC roles such as Storage Blob Data Contributor/Reader, providing granular, revocable access. This eliminates shared-key management and clearly ties each request to an application identity, aligning with the requirement to authenticate without managing credentials.
Why this answer
Azure AD authentication with managed identities allows applications to authenticate to Azure Storage without using shared keys or SAS tokens. Managed identities provide an automatically managed identity in Azure AD, enabling applications to use OAuth 2.0 tokens for secure access to storage accounts. This approach eliminates the need for any shared secrets or keys, meeting the requirement exactly.
Exam trap
The trap here is that candidates often confuse network-level controls (firewall or private endpoint) with authentication mechanisms, mistakenly believing that restricting network access alone satisfies the requirement to avoid shared keys or SAS.
How to eliminate wrong answers
Option A is wrong because a stored access policy with a shared access signature still uses a SAS token, which is a shared key-based mechanism and does not eliminate the use of shared keys. Option B is wrong because configuring a firewall on the storage account to allow only the application's IP address does not authenticate the application; it only restricts network access and still requires shared keys or SAS for authorization. Option C is wrong because enabling a private endpoint ensures private network connectivity but does not replace the need for authentication; the application still requires shared keys, SAS, or Azure AD credentials to access the storage account.