Configuring Network Access for Azure Storage Accounts

Answer Correct answer: B — Modify the Public network access settings to enable firewall rules for specific IPs.

You have an Azure subscription that contains a storage account named storage1. You need to allow access to storage1 from selected networks and your home office. The solution must minimize administrative effort. What should you do first for storage1?

  1. Add a private endpoint.
  2. Modify the Public network access settings. Correct Answer
  3. Select Internet routing.
  4. Modify the Access Control (IAM) settings.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the initial step in securing a storage account's network access; the common trap is choosing Private Endpoints or IAM, which are either too complex for simple IP-based access or unrelated to network layer restrictions.

To restrict access to an Azure storage account from selected networks and minimize administrative effort, you must first modify the Public network access settings. This allows you to enable firewall rules for specific IP ranges without requiring complex private endpoints.

Most candidates choose Option A (Private Endpoint) because they associate 'selected networks' with Private Link. However, Private Endpoints require significant configuration (subnet, private DNS) and do not natively support arbitrary public IPs like a home office without additional routing/VNet integration, violating the 'minimize administrative effort' constraint.

Community Discussion (4 comments)

Elite4Life 👍 13 Selected: B
To allow access to the storage account storage1 from selected networks and your home office while minimizing administrative effort, the first step is to modify the Public network access settings. This option allows you to specify which networks can access the storage account, including enabling access from specific IP addresses or virtual networks.
loukyy 👍 1 Selected: A
keywords: Tmust minimize administrative effort.
Pcservices 👍 4 Selected: B
To allow access to an Azure Storage account from selected networks, including your home office, you need to configure network access settings for the storage account. The first step is to modify the Public network access settings to allow access only from selected networks or specific IP addresses. Modify Public Network Access Settings: This allows you to configure the storage account so that it only accepts traffic from selected virtual networks and IP addresses, including your home office's public IP address. After modifying the network access settings, you can: Add specific IP ranges (e.g., your home office's IP) to the allowed list. Add virtual networks if there are other networks from which access should be allowed.
Henrytml 👍 4
modify the Public network access settings assumming home office doesnt not have any vpn configured to office/ Azure

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is B: Modify the Public network access settings. To allow access from specific networks (like your home office) while restricting others, you must first ensure that public network access is allowed (or specifically configured via firewalls). In Azure Storage, the 'Public network access' toggle controls whether the storage account can be reached over the public internet at all. Once enabled, you can define firewall rules allowing specific IP addresses (your home office) and virtual networks. This is the least administrative effort compared to setting up Private Endpoints.

Why the Other Options Are Wrong

Option A (Add a private endpoint) is incorrect because it requires creating a subnet, configuring private DNS zones, and managing connectivity within a VNet. It does not easily support direct access from a dynamic or non-VNet home office IP without complex workarounds. Option C (Select Internet routing) is not a standard configuration step for restricting access; routing is handled by NSGs or route tables, but access control starts with the storage account's own network settings. Option D (Modify Access Control (IAM)) manages who can read/write data (RBAC), not where connections can originate (network security).

Community Comment Notes

The community heavily favored Option B, with users noting that modifying public network access is the prerequisite for enabling firewall rules. One user highlighted that assuming no VPN is configured makes IP-based firewall rules the only viable low-effort option. Another user pointed out the keyword 'minimize administrative effort' as a clue against Private Endpoints, which aligns with the expert analysis.

Exam Strategy

Always look for keywords like 'minimize administrative effort' or 'home office' (implying public IP access). If the requirement is network-level restriction for public IPs, start with Firewall/Network settings, not Private Link or IAM.

Frequently Asked Questions

Why can't I use a Private Endpoint for my home office?

Private Endpoints require the client to be connected to a Virtual Network. Your home office typically lacks a direct VNet connection, making IP-based firewall rules via Public Network Access the simpler solution.

Does IAM control network access?

No. IAM (Access Control) manages permissions for who can perform actions on the data. Network settings control which devices/IPs can establish a connection to the storage account.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide