← AZ-104: Azure administration in production
03 / 7 · 28 MIN

Storage, delegation, and recovery

Coordinate authorization, network paths, and version protection.

Concept and mechanism

A SAS delegates bounded data operations for a defined period. Where the scenario supports it, assess user delegation SAS with Entra authorization and least privilege. Do not confuse types: stored access policies are supported by service SAS, not account SAS or user delegation SAS. Protect the token like a credential. A private endpoint creates a private path to the selected service; it does not automatically disable public access. DNS, firewall, public access, and data authorization need consistent decisions to meet an isolation requirement.

Guided application

Choose redundancy by failure scope. ZRS distributes data across zones in a region, while LRS does not provide that same distribution; geographic copies introduce other characteristics, including asynchronous replication. Redundancy does not undo an incorrect logical change. To recover an overwritten blob, previously enabled versioning may provide earlier versions to validate and restore. Archive requires rehydration before online reading, so it does not fit every immediate-access need. For AzCopy transfers, successful authentication does not prove authorization: confirm data roles, scope, and destination conditions.

IN PRACTICE

An upload fails although the user can see the storage account in the portal. Configuration Reader is not Storage Blob Data Contributor; check required data access.

Common pitfalls

Sharing an account key for a short read; assuming isolation from a private IP alone; using redundancy as the only recovery plan.

Related topics: Declarative deployments and virtual machines · Availability, scale, and releases

Take this idea with you

Protect the path, credential, and recoverable data state as related decisions.

Create account

Reference: Storage private endpoints · AZ-104; skills measured 2026-04-17