How Do You Warn Users When a SAS Exceeds Seven Days?
You have an Azure subscription that contains a storage account named storage. The storage account contains a blob that stores images. Client access to storage1 is granted by using a shared access signature (SAS). You need to ensure that users receive a warning message when they generate a SAS that exceeds a seven-day time period. What should you do for storage?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This item tests the difference between a soft SAS expiry policy (a warning shown at generation time) and unrelated storage controls, and the trap is reaching for a lock, an alert rule or a lifecycle rule instead of the storage account's SAS expiration policy.
Azure Storage lets you enforce a SAS expiration policy on a storage account so that any shared access signature generated past a defined interval triggers a warning to the user who created it. Setting the recommended upper limit for the SAS expiry interval to Enabled (option D) is what produces that advisory message for SAS tokens longer than seven days.
Many candidates pick 'Configure an alert rule' (B) because the question says 'warning message'; Azure Monitor alerts fire after resource telemetry events, while the SAS expiry policy warns the user interactively in the portal, CLI or SDK at the moment the SAS is created.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure Storage lets a storage account owner publish a SAS expiration policy under the account's Configuration blade, in the Shared access signature (SAS) settings section. Within that policy you set a maximum expiry interval (for example seven days) and then choose whether the recommended upper limit is Disabled, Enabled or Required. With Allow recommended upper limit for shared access signature (SAS) expiry interval set to Enabled, the policy is advisory: a user who generates a SAS whose expiry exceeds the documented interval still succeeds, but immediately receives a warning explaining that the SAS lasts longer than the recommended limit. That is exactly the behaviour the question asks for — "users receive a warning message when they generate a SAS that exceeds a seven-day time period." Setting the value to Required would be stricter: it would block generation of any SAS beyond the limit rather than warn, so Enabled is the precise fit here. This is a storage-account-level configuration, so it is applied once on thestorage account and covers all SAS types generated for that account (service, account and user delegation SAS).Why the Other Options Are Wrong
A. Enable a read-only lock. ACanNotDelete/read-only management lock only prevents modification or deletion of the storage account resource in Azure Resource Manager. It has no visibility into SAS token generation and cannot emit any message to the user creating a signature.
B. Configure an alert rule. An Azure Monitor alert rule evaluates metrics, activity-log events or log queries and notifies configured action groups when a threshold is breached. It is a monitoring/notification construct, not an interactive warning at SAS-creation time, and there is no metric that would reproduce the built-in policy warning.
C. Add a lifecycle management rule. Lifecycle management rules move or delete blobs in a storage account (for example, tiering to Cool or deleting blobs older than N days). They govern blob data retention and have nothing to do with the lifetime of a SAS token.Community Comment Notes
Shakka walked through the exact portal path, describing navigation to the storage account and then to Configuration where you find the SAS expiration policy and set the recommended upper limit, which matches the documented procedure. sca88 posted the Microsoft Learn article on the SAS expiration policy, confirming that the vendor documentation is the authoritative source for this scenario. KAM2023 and Sweden2022 both recorded straightforward confirmations that D is correct, and no commenter proposed a competing option, so the community consensus (100% for D) aligns with the official behaviour.Official Reference
Exam Strategy
When an AZ-104 item asks for a 'warning' about a SAS property, look first for a storage-account SAS policy setting rather than a monitoring artefact. Remember the three states — Disabled, Enabled (warn) and Required (block) — and pick the one whose wording matches 'warn' versus 'prevent'.
Frequently Asked Questions
Why does an alert rule not deliver the SAS expiry warning?
Alert rules act on metrics, activity logs or log queries and notify action groups asynchronously; they cannot display an interactive warning to the person generating the SAS, which the SAS expiry policy does.
What is the difference between Enabled and Required in the SAS expiration policy?
Enabled warns the user but still allows the longer SAS to be created; Required blocks creation of any SAS whose expiry exceeds the configured interval.
Related Analysis
Practice All AZ-104 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-104 Practice Test →