How Do You Rotate Azure Storage Account Access Keys Automatically?
You have an Azure subscription that contains a storage account named storage1. You need to ensure that the access keys for storage1 rotate automatically. What should you configure?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests which Azure service can regenerate storage account keys on a schedule; the trap is confusing any 'vault' or any Key Vault-adjacent feature (backup vaults, Recovery Services vaults) with the Key Vault managed-storage-account feature that actually performs rotation.
Azure Storage account access keys rotate automatically only when the account is registered as a managed storage account in Azure Key Vault, which regenerates the keys on a schedule you define. This page confirms Azure Key Vault (D) as the correct configuration and explains why redundancy, lifecycle management, and vault types for backup cannot rotate keys.
Picking 'a Recovery Services vault' (E) or 'a backup vault' (A) because the word 'vault' sounds like the place credentials and secrets are protected; those vaults store backup data and have no ability to regenerate storage1's access keys.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure Key Vault is the only service listed that can both hold storage1's access keys and rotate them on a schedule. By adding the storage account as a managed storage account in Key Vault, you choose either Key Vault-managed rotation (for example every 30 or 90 days) or a custom rotation period, and Key Vault regenerateskey1/key2 and updates the stored secret automatically. This is exactly what the question asks for: unattended, automatic rotation of the storage account access keys. As exa104az puts it, "Azure Key Vault is a service that helps manage secrets, keys, and certificates" and its rotation feature automates the key lifecycle. Separating key management from the storage account itself also means applications can read a secret from Key Vault rather than hard-coding the key.Why the Other Options Are Wrong
A backup vault and a Recovery Services vault (E) are data-protection constructs that hold backup items and recovery points; the shared word "vault" is the only link to key management, and neither can regenerate a storage account key. Redundancy for storage1 (B) — LRS, ZRS, GRS, or RA-GZRS — copies data across fault domains and regions, which protects durability, not credential rotation. Lifecycle management for storage1 (C) is a blob policy that transitions or deletes blobs based on age or last-access time; it never touches the account keys. None of these options can invalidate and reissue keys on a timer.Community Comment Notes
Learner consensus is unanimous: the vote record is 100% for D, and every comment endorses it. 6c05b3d states that you "should configure Azure Key Vault with Azure Storage account key rotation," which is precisely the managed-storage-account behavior. The terse replies from alsmk2 ("Correct") and behradcld ("simple as cake") reflect how quickly the answer falls out once you know the Key Vault rotation feature exists. The consistent point across the thread is that rotation is a Key Vault capability, not a storage-account property.Key Vault Rotation Mechanics to Remember
When Key Vault manages the account, you can use Key Vault-managed rotation (which regenerates only the key not currently in use, then swaps) or a custom period; you should also set up an Event Grid notification to re-sync dependent services. This distinction matters on the exam because it separates "storing a key as a secret" from "having Key Vault actively rotate it."Official Reference
Exam Strategy
When a question contains the phrase "rotate automatically," map it to a service that owns a rotation policy — for storage keys that is Azure Key Vault managed storage accounts, just as automated secret rotation never comes from a backup or redundancy feature. Eliminate options that manage copies of data (redundancy, lifecycle, backup vaults) before comparing the remaining candidates.
Frequently Asked Questions
Why can't a Recovery Services vault rotate storage1's access keys?
A Recovery Services vault stores backup items and recovery points for VMs, files and workloads. It has no key-management API, so it cannot regenerate storage account access keys on a schedule.
Does lifecycle management ever change storage account access keys?
No. Lifecycle management policies only transition or delete blobs in the account based on age or last-access time; the account's key1 and key2 values are untouched.
Related Analysis
Practice All AZ-104 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-104 Practice Test →