QuestionQ26

Develop for Azure storage

You develop a REST API and implement a user delegation SAS token to communicate with Azure Blob storage.

The token has been compromised. You need to revoke it.

What are two possible ways to accomplish this goal? Each correct answer provides a complete solution.

NOTE: Each correct selection is worth one point.

Choose two
Explanation

A user delegation SAS can be revoked by revoking its user delegation key, which invalidates SAS tokens signed with that key. It can also be revoked by changing or removing the RBAC role assignment for the security principal used to create the SAS, because Azure Storage verifies that principal’s required permissions when the SAS is used. Stored access policies and storage account-key regeneration do not revoke a user delegation SAS.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!