Courseiva

Azure Files On-Premises AD Authentication — Enforce Active Directory Credentials

Your organization uses Azure Files shares. You need to ensure that users authenticate using on-premises Active Directory credentials and that access is logged. What should you do?

⚠ Common exam trap

Watch out — candidates often confuse Azure RBAC (which controls management-plane access) with identity-based authentication for data-plane access, or they mistakenly think SAS tokens or firewall rules can satisfy both authentication and logging requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable identity-based authentication for Azure Files and configure diagnostic logs

Azure Files supports identity-based authentication using on-premises Active Directory Domain Services (AD DS) via Kerberos. This allows users to authenticate with their on-premises AD credentials and access the file share seamlessly. Enabling diagnostic logs captures access events, meeting the logging requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a firewall rule to allow on-premises IPs and enable diagnostic logs

    Why it's wrong here

    A firewall rule merely filters traffic by source IP address and does not perform any user authentication. On-premises users would still be challenged by Azure Files SMB, and without identity-based authentication they cannot present AD credentials that Azure Files validates. Enabling diagnostic logs captures access failures and successes, but logging cannot compensate for the missing authentication mechanism. Therefore this option does not meet the requirement for authenticating on-premises identities.

  • ✗

    Use shared access signatures (SAS) for access and enable diagnostic logs

    Why it's wrong here

    Shared access signatures delegate access using an account key or stored access policy, so they are tied to the key, not to an individual on-premises AD account. This means each user would need a SAS token distributed out-of-band, and there is no Kerberos ticket exchange against the on-premises domain controller. While diagnostic logs can trace token usage, they cannot authenticate users in this model. This fails because the goal is to use on-premises identities for access.

  • ✓

    Enable identity-based authentication for Azure Files and configure diagnostic logs

    Why this is correct

    Enabling identity-based authentication for Azure Files lets SMB clients authenticate with Kerberos using either Microsoft Entra Domain Services or an on-premises AD DS domain, so user access is tied to actual directory identities. After authentication, Azure Files enforces both RBAC share-level roles and Windows ACLs on directories and files. Configuring diagnostic logs then gives you audit trails of which identity performed which operation. This fully satisfies the requirement.

  • ✗

    Configure Azure RBAC for the share and enable diagnostic logs

    Why it's wrong here

    Azure RBAC defines authorization by assigning roles like Storage File Data SMB Share Reader to your share, but RBAC role assignment does not verify a user’s password or Kerberos ticket. For an on-premises AD user to be authenticated, the storage account must be domain joined and identity-based authentication enabled so the Kerberos SID can be mapped to an Microsoft Entra ID identity. Without that, RBAC roles are effectively unusable for those users, and diagnostic logs only record authorization failures. This option mixes up authorization with authentication.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.