Configuring Network Access for Azure Storage Accounts
You have an Azure subscription that contains a storage account named storage1. You need to allow access to storage1 from selected networks and your home office. The solution must minimize administrative effort. What should you do first for storage1?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the initial step in securing a storage account's network access; the common trap is choosing Private Endpoints or IAM, which are either too complex for simple IP-based access or unrelated to network layer restrictions.
To restrict access to an Azure storage account from selected networks and minimize administrative effort, you must first modify the Public network access settings. This allows you to enable firewall rules for specific IP ranges without requiring complex private endpoints.
Most candidates choose Option A (Private Endpoint) because they associate 'selected networks' with Private Link. However, Private Endpoints require significant configuration (subnet, private DNS) and do not natively support arbitrary public IPs like a home office without additional routing/VNet integration, violating the 'minimize administrative effort' constraint.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is B: Modify the Public network access settings. To allow access from specific networks (like your home office) while restricting others, you must first ensure that public network access is allowed (or specifically configured via firewalls). In Azure Storage, the 'Public network access' toggle controls whether the storage account can be reached over the public internet at all. Once enabled, you can define firewall rules allowing specific IP addresses (your home office) and virtual networks. This is the least administrative effort compared to setting up Private Endpoints.Why the Other Options Are Wrong
Option A (Add a private endpoint) is incorrect because it requires creating a subnet, configuring private DNS zones, and managing connectivity within a VNet. It does not easily support direct access from a dynamic or non-VNet home office IP without complex workarounds. Option C (Select Internet routing) is not a standard configuration step for restricting access; routing is handled by NSGs or route tables, but access control starts with the storage account's own network settings. Option D (Modify Access Control (IAM)) manages who can read/write data (RBAC), not where connections can originate (network security).Community Comment Notes
The community heavily favored Option B, with users noting that modifying public network access is the prerequisite for enabling firewall rules. One user highlighted that assuming no VPN is configured makes IP-based firewall rules the only viable low-effort option. Another user pointed out the keyword 'minimize administrative effort' as a clue against Private Endpoints, which aligns with the expert analysis.Exam Strategy
Always look for keywords like 'minimize administrative effort' or 'home office' (implying public IP access). If the requirement is network-level restriction for public IPs, start with Firewall/Network settings, not Private Link or IAM.
Frequently Asked Questions
Why can't I use a Private Endpoint for my home office?
Private Endpoints require the client to be connected to a Virtual Network. Your home office typically lacks a direct VNet connection, making IP-based firewall rules via Public Network Access the simpler solution.
Does IAM control network access?
No. IAM (Access Control) manages permissions for who can perform actions on the data. Network settings control which devices/IPs can establish a connection to the storage account.
Related Analysis
Practice All AZ-104 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-104 Practice Test →