Pool1 uses Storage1\share1 to store FSLogix profile containers. You created Group1 and granted it sign-in permission to Pool1. To allow Group1 members to write FSLogix containers to share1 using least privilege, which two privileges should you assign?
Choose an answer
Tap an option to check your answer.
Correct answer: the Modify NTFS permissions for share1, the Storage File Data SMB Share Contributor role for storage1.
Why this is the answer
For FSLogix profile containers, users need both share-level and NTFS-level permissions. The Storage File Data SMB Share Contributor role grants the necessary share-level permissions (read, write, and delete) for Azure file shares, allowing users to create and modify their profile disks. The Modify NTFS permission for share1 grants the necessary NTFS-level permissions, including the ability to create, write, and delete files and folders within their profile. The Storage Blob Data Contributor role is for Azure Blob Storage, not Azure Files. Storage File Data SMB Share Reader is insufficient as it only provides read access. Storage File Data SMB Share Elevated Contributor provides excessive permissions. List folder / read data NTFS permissions are insufficient for writing profiles.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed