An Azure subscription contains a storage account storage1 with a file share share1. The subscription is linked to a hybrid Azure AD tenant that has a security group Group1. You must give Group1 the Storage File Data SMB Share Elevated Contributor role for share1. What is the first step you should take?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Active Directory Domain Service (AD DS) authentication for storage1..
Why this is the answer
To assign Azure AD security principals (like Group1) role-based access control (RBAC) permissions to an Azure file share, you must first enable Active Directory Domain Services (AD DS) authentication for the storage account. This integrates the storage account with your on-premises AD DS, allowing Azure AD Connect to synchronize identities and enabling AD DS-based authentication for file share access. Without enabling AD DS authentication, Azure AD identities cannot be directly used for RBAC assignments on file shares. Granting share-level permissions via File Explorer or mounting the share are subsequent steps, not the initial prerequisite for RBAC. Creating a private endpoint enhances network security but doesn't enable AD DS authentication for file shares.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed