Concept and mechanism
A SAS delegates bounded data operations for a defined period. Where the scenario supports it, assess user delegation SAS with Entra authorization and least privilege. Do not confuse types: stored access policies are supported by service SAS, not account SAS or user delegation SAS. Protect the token like a credential. A private endpoint creates a private path to the selected service; it does not automatically disable public access. DNS, firewall, public access, and data authorization need consistent decisions to meet an isolation requirement.
Guided application
Choose redundancy by failure scope. ZRS distributes data across zones in a region, while LRS does not provide that same distribution; geographic copies introduce other characteristics, including asynchronous replication. Redundancy does not undo an incorrect logical change. To recover an overwritten blob, previously enabled versioning may provide earlier versions to validate and restore. Archive requires rehydration before online reading, so it does not fit every immediate-access need. For AzCopy transfers, successful authentication does not prove authorization: confirm data roles, scope, and destination conditions.
An upload fails although the user can see the storage account in the portal. Configuration Reader is not Storage Blob Data Contributor; check required data access.
Common pitfalls
Sharing an account key for a short read; assuming isolation from a private IP alone; using redundancy as the only recovery plan.
Related topics: Declarative deployments and virtual machines · Availability, scale, and releases
Protect the path, credential, and recoverable data state as related decisions.
Reference: Storage private endpoints · AZ-104; skills measured 2026-04-17