Account keys, account and service SAS, user delegation SAS and Entra RBAC compared by scope and revocability.
From Ultra Transcenders SC-500 by Tony Rough (publishing soon)
Once a request reaches the account, it must be authorised. Each method differs in which services it works with, how narrowly it can be scoped and whether it expires. Figure 5.1 ranks the methods from the broadest and least revocable to the most controlled.
| Method | Blob / Table | Azure Files SMB | Scope and lifetime |
|---|---|---|---|
| Shared Key (account key) | Yes | Yes (mount uses NTLMv2) | Full access to every service in the account, never expires |
| SAS | Yes | No | Chosen permissions, resources, start and expiry |
| Microsoft Entra ID OAuth (RBAC) | Yes | No (REST only) | Standing permissions, no built-in expiry |
| Kerberos (AD DS, Microsoft Entra Domain Services, Microsoft Entra Kerberos) | No | Yes | Identity-based SMB |
| Anonymous public access | Blob read only | No | Everyone |
This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · Free SC-500 glossary · All SC-500 study notes
How PIM activation, approval, maximum duration and notifications work, and what each role setting controls.
How a Conditional Access policy is built and how multiple policies combine.
Why control-plane roles can't read secrets, and which Key Vault role or access policy each task needs.
What Deny, Audit, Append, Modify and DeployIfNotExists do, and when you need a remediation task and managed identity.
Where each Azure SQL data protection feature works and who it protects data from.
How security admin rules are evaluated before NSGs, and when to use Allow, Deny or Always allow.
How JIT locks management ports and opens them on request, with the plan and permissions it needs.