How Does a Service Endpoint Policy Enable Paired-Region Storage Access?
You have an Azure subscription. The subscription contains a locally-redundant storage (LRS) account named storage1 that is deployed to the US East Azure region and has a Microsoft.Storage service endpoint. You set Redundancy for storage1 to Read-access geo-redundant storage (RA-GRS). You need to ensure that the contents of storage1 will be accessible by using a service endpoint in a paired region. The solution must minimize administrative effort. What should you do first?
Community Votes
66% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tested: applying a service endpoint policy upgrades the Azure Storage service endpoint scope from regional to global; the trap is assuming RA-GRS replication, or deleting/recreating the endpoint, is what exposes the paired region.
A subnet's Microsoft.Storage service endpoint is region-scoped by default, so storage1's RA-GRS secondary endpoints in the paired region stay unreachable until a service endpoint policy is applied. This AZ-700 page confirms answer D — creating the service endpoint policy is the first, lowest-effort step.
Picking A (object replication) because the scenario mentions a paired region; object replication copies blob data between accounts and adds rules and prerequisites, but it never changes what the subnet's service endpoint can reach.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft's service endpoint policy documentation states that once a policy is applied on a subnet, the Azure Storage service endpoint scope is upgraded from regional to global, after which traffic to Azure Storage is secured over service endpoints wherever the account lives. That is exactly the blocker in this scenario: the subnet in US East has a Microsoft.Storage endpoint, but a regional endpoint only covers storage accounts in the VNet's own region, even though RA-GRS has given storage1 read-only secondary endpoints in its paired region. Creating a service endpoint policy (and allowing storage1 in it) is therefore the action that makes the paired-region content reachable, and it is also the minimum-effort option — no data copy, no endpoint teardown, no per-region endpoint plumbing. The word "first" in the question points at this scope-changing step rather than at anything done afterwards. Because the question asks what to do first and the scope upgrade happens the moment a policy is attached, D is the only option that directly satisfies the requirement.Why the Other Options Are Wrong
A (object replication) is a data-copy feature that replicates block blobs from one storage account to another, typically in the paired region; it requires source and destination accounts, versioning, and replication rules, which is a lot of administrative effort and does not extend the service endpoint at all. B (delete the existing service endpoint) is the opposite of what is needed: removing the endpoint strips storage1 of its current service-endpoint access, and recreating the same endpoint simply returns it to regional scope, so the paired region remains unreachable. C (Secure transfer required) only enforces HTTPS/TLS for requests to the account; it is a transport-security setting with no bearing on which regions the service endpoint can address. None of A, B, or C changes the regional-to-global scope of the Microsoft.Storage endpoint, which is the actual requirement.Community Comment Notes
NK203 captures the decisive doc behavior verbatim — that when policies are applied on a subnet, "the Azure Storage Service Endpoint scope gets upgraded from regional to global" — which is why the vote count of 67 for D matches the official overview page. alexastein and xRiot007 both cite the service endpoint policies overview as the justification for D, and xRiot007 frames it as using a policy to control what the VNet may reach over the endpoint. sismer argues for A, reasoning that object replication would place the contents in a paired region, but that answer moves data rather than making the existing endpoint global, so it misses the requirement. bobothewiseman first settled on D, then switched to B on the premise that "service endpoints are tied to the original region" — that premise is correct, but deleting the endpoint does not widen its scope, so the B rationale collapses.Official Reference
Exam Strategy
When AZ-700 asks how a subnet reaches storage in a paired region over a service endpoint, look for the feature that changes the endpoint's scope, not the one that moves data. Also treat "what should you do first" and "minimize administrative effort" as filters: policy creation beats replication rules, and deleting/recreating an endpoint never changes its regional scope.
Frequently Asked Questions
Why doesn't RA-GRS alone make storage1 reachable from a paired region over a service endpoint?
RA-GRS adds read-only secondary endpoints for storage1 in its paired region, but the subnet's Microsoft.Storage service endpoint stays region-scoped until a service endpoint policy is applied to that subnet.
Why is deleting the existing service endpoint (option B) not the fix?
Deleting the endpoint drops storage1's current service-endpoint access and does not change the endpoint's regional scope; recreating it returns the same regional endpoint, leaving the paired region unreachable.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →