Exam AZ-104 Topic 1 Question 319 Discussion

Actual exam question for Microsoft's AZ-104 exam
Question #: 319
Topic #: 1
You have an Azure Storage account named storage1.
You have an Azure App Service app named app1 and an app named App2 that runs in an Azure container instance. Each app uses a managed identity.
You need to ensure that App1 and App2 can read blobs from storage1 for the next 30 days.
What should you configure in storage1 for each app?

Exhibit

Suggested Answer:


Explanation:
Detailed Explanation
For App1, the Azure-recommended, credential-less way to grant a web app ' s managed identity read access to blob data is via Access control (IAM), assigning the built-in Storage Blob Data Reader role to the identity ' s service principal - this avoids managing keys and can be scoped/revoked at any time, satisfying the 30-day window by removing the assignment later. For App2 running in Container Instances, direct Azure AD
/managed-identity based data-plane access to Storage requires custom in-container code to request and present a token, which is not the standard configuration path; the practical approach is to configure a Shared Access Signature scoped to Read on the container/blobs with an explicit 30-day expiry, handed to App2. Access keys grant unscoped full account access (not least privilege) and Advanced security only enables Defender for Storage threat detection, not access grants.
Official Reference
Authorize access to blob data with managed identities for Azure resources - https://learn.microsoft.com/en- us/azure/storage/common/storage-auth-aad-msi

by Galee at Oct 07, 2026, 12:54 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
Galee
2026-10-07 12:54:48
The App2 = SAS answer appears outdated/questionable. Microsoft’s current documentation states that Azure Container Instances supports managed identities and that a container’s managed identity can be granted access to Azure resources such as a storage account. Azure Storage also supports blob data authorization through Microsoft Entra ID/RBAC for managed identities. Therefore, since App2 already has a managed identity, assigning Storage Blob Data Reader through Access control (IAM) should allow App2 to read blobs, just like App1. SAS would make sense if the requirement explicitly said the access must automatically expire after 30 days, but the question only says the apps need access “for the next 30 days.” Please review whether App2 should also be IAM.
upvoted 1 times
...
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10