A partner application needs read-only access to a single blob in a container for 24 hours. Your security team requires that storage account access keys are never used or distributed. What is the MOST secure way to grant this access?
Choose one.
When granting temporary, delegated access to blob data, prefer a user delegation SAS: it is signed with Microsoft Entra ID credentials, can be scoped tightly to a resource and permission set, and avoids ever handling account keys.
The user delegation SAS satisfies every constraint: no account key is used in signing, the scope is a single blob, the permission is read-only, and the expiry is 24 hours. The account SAS and service SAS options both fail because their signatures require an account access key, and the account SAS additionally over-grants across services. Handing out the access key itself is the worst option because keys confer full, non-scoped access to all data in the account.
- Note the constraint: account access keys must not be used or shared, which eliminates account SAS, service SAS, and direct key distribution.
- Choose the user delegation SAS, which is signed with an Entra-issued user delegation key.
- Scope the SAS to the specific blob, grant only the read permission, and set the expiry to 24 hours.
- Deliver the SAS URL to the partner over a secure channel and require HTTPS-only access.
Exam tip: For time-limited delegated access without touching account keys, issue a tightly scoped user delegation SAS.
Configure Access to Azure Storage: SAS, Keys & Firewalls (AZ-104) — the lesson that teaches this.