You're enabling Azure AD authentication for storage1 and need members of Group1 to be able to upload files via the Azure portal while following least privilege. Which two roles should you assign for storage1?
Choose an answer
Tap an option to check your answer.
Correct answer: Storage Blob Data Contributor, Reader.
Why this is the answer
To upload files, members of Group1 need data plane access to perform write operations on blobs. The Storage Blob Data Contributor role grants read, write, and delete access to Azure storage blob containers and data, satisfying the requirement for uploading files. Additionally, to view the storage account and its containers in the Azure portal, the Reader role is necessary. This role provides read-only access to Azure resources, allowing users to navigate and see the storage account without modifying its configuration. Storage Account Contributor and Contributor are too permissive as they grant management plane access to the storage account itself, not just data plane access to blobs, violating the principle of least privilege. Storage Blob Data Reader only allows read access to blobs, which is insufficient for uploading files.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed