QuestionQ37

Manage storage and file services

Your network has an on-premises Active Directory Domain Services (AD DS) domain. The domain includes servers running Windows Server and a group named Group1.

You have an Azure Storage account containing an Azure Files share named share1. Identity-based authentication for Azure Files is enabled by using the domain. Group1 synchronizes with a Microsoft Entra tenant.

Members of Group1 can authenticate from the servers, but they cannot access the files in share1. Group1 has Modify NTFS permissions on the required folders in share1.

You need to grant Group1 share-level access that meets these requirements:

  • Allow members to read, write, and delete files through SMB.
  • Prevent members from changing the NTFS permissions.
  • Follow the principle of least privilege.

Which role should you assign to Group1 at the scope of share1?

Explanation

The Storage File Data SMB Share Contributor role grants read, write, and delete access to Azure Files over SMB. Combined with the existing Modify NTFS permissions, it permits the required file operations. Unlike Storage File Data SMB Share Elevated Contributor and Storage File Data Privileged Contributor, it does not grant permission to modify NTFS ACLs, making it the least-privilege role.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!