How Do You Warn Users When a SAS Exceeds Seven Days?

Answer Correct answer: D — Enable the 'Allow recommended upper limit for shared access signature (SAS) expiry interval' setting on the storage account's SAS expiration policy to warn users when a SAS exceeds seven days.

You have an Azure subscription that contains a storage account named storage. The storage account contains a blob that stores images. Client access to storage1 is granted by using a shared access signature (SAS). You need to ensure that users receive a warning message when they generate a SAS that exceeds a seven-day time period. What should you do for storage?

  1. Enable a read-only lock.
  2. Configure an alert rule.
  3. Add a lifecycle management rule.
  4. Set Allow recommended upper limit for shared access signature (SAS) expiry interval to Enabled. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This item tests the difference between a soft SAS expiry policy (a warning shown at generation time) and unrelated storage controls, and the trap is reaching for a lock, an alert rule or a lifecycle rule instead of the storage account's SAS expiration policy.

Azure Storage lets you enforce a SAS expiration policy on a storage account so that any shared access signature generated past a defined interval triggers a warning to the user who created it. Setting the recommended upper limit for the SAS expiry interval to Enabled (option D) is what produces that advisory message for SAS tokens longer than seven days.

Many candidates pick 'Configure an alert rule' (B) because the question says 'warning message'; Azure Monitor alerts fire after resource telemetry events, while the SAS expiry policy warns the user interactively in the portal, CLI or SDK at the moment the SAS is created.

Community Discussion (6 comments)

58b2872 👍 1 Selected: D
To ensure users receive warnings when generating SAS tokens that exceed a 7-day expiry, D. Set Allow recommended upper limit for shared access signature (SAS) expiry interval to Enabled is the correct choice.
sca88 👍 2 Selected: D
https://learn.microsoft.com/en-us/azure/storage/common/sas-expiration-policy?tabs=azure-portal
Sweden2022 👍 1 Selected: D
D is correct.
KAM2023 👍 3 Selected: D
Correct
Shakka 👍 4 Selected: D
D Correct Sign in to the Azure portal: Ensure you have the necessary administrative privileges. Navigate to the Storage Account: Go to Storage accounts and select the storage account named storage. Configure the SAS Expiration Policy: In the storage account settings, go to Configuration. Under Shared access signature (SAS) settings, find the SAS expiration policy. Set the Recommended upper limit for SAS expiration to 7 day
DJHASH786 👍 1
Correct Answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure Storage lets a storage account owner publish a SAS expiration policy under the account's Configuration blade, in the Shared access signature (SAS) settings section. Within that policy you set a maximum expiry interval (for example seven days) and then choose whether the recommended upper limit is Disabled, Enabled or Required. With Allow recommended upper limit for shared access signature (SAS) expiry interval set to Enabled, the policy is advisory: a user who generates a SAS whose expiry exceeds the documented interval still succeeds, but immediately receives a warning explaining that the SAS lasts longer than the recommended limit. That is exactly the behaviour the question asks for — "users receive a warning message when they generate a SAS that exceeds a seven-day time period." Setting the value to Required would be stricter: it would block generation of any SAS beyond the limit rather than warn, so Enabled is the precise fit here. This is a storage-account-level configuration, so it is applied once on the storage account and covers all SAS types generated for that account (service, account and user delegation SAS).

Why the Other Options Are Wrong

A. Enable a read-only lock. A CanNotDelete/read-only management lock only prevents modification or deletion of the storage account resource in Azure Resource Manager. It has no visibility into SAS token generation and cannot emit any message to the user creating a signature. B. Configure an alert rule. An Azure Monitor alert rule evaluates metrics, activity-log events or log queries and notifies configured action groups when a threshold is breached. It is a monitoring/notification construct, not an interactive warning at SAS-creation time, and there is no metric that would reproduce the built-in policy warning. C. Add a lifecycle management rule. Lifecycle management rules move or delete blobs in a storage account (for example, tiering to Cool or deleting blobs older than N days). They govern blob data retention and have nothing to do with the lifetime of a SAS token.

Community Comment Notes

Shakka walked through the exact portal path, describing navigation to the storage account and then to Configuration where you find the SAS expiration policy and set the recommended upper limit, which matches the documented procedure. sca88 posted the Microsoft Learn article on the SAS expiration policy, confirming that the vendor documentation is the authoritative source for this scenario. KAM2023 and Sweden2022 both recorded straightforward confirmations that D is correct, and no commenter proposed a competing option, so the community consensus (100% for D) aligns with the official behaviour.

Official Reference

Exam Strategy

When an AZ-104 item asks for a 'warning' about a SAS property, look first for a storage-account SAS policy setting rather than a monitoring artefact. Remember the three states — Disabled, Enabled (warn) and Required (block) — and pick the one whose wording matches 'warn' versus 'prevent'.

Frequently Asked Questions

Why does an alert rule not deliver the SAS expiry warning?

Alert rules act on metrics, activity logs or log queries and notify action groups asynchronously; they cannot display an interactive warning to the person generating the SAS, which the SAS expiry policy does.

What is the difference between Enabled and Required in the SAS expiration policy?

Enabled warns the user but still allows the longer SAS to be created; Required blocks creation of any SAS whose expiry exceeds the configured interval.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide