Azure Service Endpoint Policy Storage Access
You have an Azure subscription that contains the resources shown in the following table. You create a service endpoint policy that has the following settings: • Associated subnets: Subnet1 • Service: Microsoft.Storage • Scope: Single account • Resource: storage1 Which resources can VM1 access? - 
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Service endpoint policies test your understanding of replication behavior; the common trap is assuming only the primary region is accessible when a single account is specified.
An Azure service endpoint policy scoped to a single storage account restricts subnet traffic to that specific account. This page establishes that such a policy automatically includes access to the storage account's geo-redundant replica in the paired region.
Choosing Option B (primary region only) because the policy explicitly lists only one resource, forgetting that geo-redundant replicas are automatically included for high availability.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When a service endpoint policy is configured with a scope of Single account and targets a specific storage account (storage1), it restricts outbound traffic from the associated subnet to only that storage account. However, Azure's platform behavior dictates that if the storage account uses geo-redundant replication, access to the secondary instance in the paired region is automatically allowed when the primary is allowed. Therefore, VM1 can access storage1 in its primary East US region and its replica in the paired region.Why the Other Options Are Wrong
Option B is incorrect because it fails to account for the automatic access granted to the geo-redundant replica in the paired region, which is a built-in feature of service endpoint policies for storage. Option C is incorrect because the policy scope is set to Single account (storage1), which explicitly blocks access to other storage accounts like storage2 in the same region. Option D is incorrect for the same reason; storage2 is not defined in the policy's allowed resource list and is therefore blocked, along with its replica.Community Comment Notes
Commenters correctly highlighted the automatic replica access, with pringlez28 citing the official documentation stating "RA-GRS secondary access is automatically allowed if the primary account is listed." Asheesh22 also noted that "It will allow automatic access of its Replica," confirming the community consensus on this built-in behavior.Official Reference
Exam Strategy
For service endpoint policy questions, remember that a single account scope restricts traffic strictly to the named resource but automatically includes its geo-redundant replica in the paired region. Do not assume the policy only applies to the primary region endpoint.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →