Azure Files On-Premises AD Authentication — Enforce Active Directory Credentials
Your organization uses Azure Files shares. You need to ensure that users authenticate using on-premises Active Directory credentials and that access is logged. What should you do?
⚠ Common exam trap
Watch out — candidates often confuse Azure RBAC (which controls management-plane access) with identity-based authentication for data-plane access, or they mistakenly think SAS tokens or firewall rules can satisfy both authentication and logging requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable identity-based authentication for Azure Files and configure diagnostic logs
Azure Files supports identity-based authentication using on-premises Active Directory Domain Services (AD DS) via Kerberos. This allows users to authenticate with their on-premises AD credentials and access the file share seamlessly. Enabling diagnostic logs captures access events, meeting the logging requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a firewall rule to allow on-premises IPs and enable diagnostic logs
Why it's wrong here
A firewall rule merely filters traffic by source IP address and does not perform any user authentication. On-premises users would still be challenged by Azure Files SMB, and without identity-based authentication they cannot present AD credentials that Azure Files validates. Enabling diagnostic logs captures access failures and successes, but logging cannot compensate for the missing authentication mechanism. Therefore this option does not meet the requirement for authenticating on-premises identities.
- ✗
Use shared access signatures (SAS) for access and enable diagnostic logs
Why it's wrong here
Shared access signatures delegate access using an account key or stored access policy, so they are tied to the key, not to an individual on-premises AD account. This means each user would need a SAS token distributed out-of-band, and there is no Kerberos ticket exchange against the on-premises domain controller. While diagnostic logs can trace token usage, they cannot authenticate users in this model. This fails because the goal is to use on-premises identities for access.
- ✓
Enable identity-based authentication for Azure Files and configure diagnostic logs
Why this is correct
Enabling identity-based authentication for Azure Files lets SMB clients authenticate with Kerberos using either Microsoft Entra Domain Services or an on-premises AD DS domain, so user access is tied to actual directory identities. After authentication, Azure Files enforces both RBAC share-level roles and Windows ACLs on directories and files. Configuring diagnostic logs then gives you audit trails of which identity performed which operation. This fully satisfies the requirement.
- ✗
Configure Azure RBAC for the share and enable diagnostic logs
Why it's wrong here
Azure RBAC defines authorization by assigning roles like Storage File Data SMB Share Reader to your share, but RBAC role assignment does not verify a user’s password or Kerberos ticket. For an on-premises AD user to be authenticated, the storage account must be domain joined and identity-based authentication enabled so the Kerberos SID can be mapped to an Microsoft Entra ID identity. Without that, RBAC roles are effectively unusable for those users, and diagnostic logs only record authorization failures. This option mixes up authorization with authentication.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.