FREE STUDY NOTES · SC-500

Choosing a storage authorisation method: keys, SAS types and Microsoft Entra ID

Account keys, account and service SAS, user delegation SAS and Entra RBAC compared by scope and revocability.

From Ultra Transcenders SC-500 by Tony Rough (publishing soon)

Once a request reaches the account, it must be authorised. Each method differs in which services it works with, how narrowly it can be scoped and whether it expires. Figure 5.1 ranks the methods from the broadest and least revocable to the most controlled.

A ladder of five storage authorisation methods: account key, account SAS, service SAS, user delegation SAS, and Microsoft Entra ID with RBAC data roles. For each it shows what signs or authorises it and what limits it. Dashed boxes mark the methods that rely on the account key, which regenerating both keys invalidates.
Figure 5.1: Storage authorisation methods, from the broadest and least revocable to the most controlled
Method Blob / Table Azure Files SMB Scope and lifetime
Shared Key (account key) Yes Yes (mount uses NTLMv2) Full access to every service in the account, never expires
SAS Yes No Chosen permissions, resources, start and expiry
Microsoft Entra ID OAuth (RBAC) Yes No (REST only) Standing permissions, no built-in expiry
Kerberos (AD DS, Microsoft Entra Domain Services, Microsoft Entra Kerberos) No Yes Identity-based SMB
Anonymous public access Blob read only No Everyone

Get the whole book

This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · Free SC-500 glossary · All SC-500 study notes

More SC-500 study notes