How Does a Service Endpoint Policy Enable Paired-Region Storage Access?

Design and implement service endpoints
Answer Correct answer: D — Create a service endpoint policy to upgrade the Microsoft.Storage endpoint scope from regional to global so storage1 is reachable in the paired region.

You have an Azure subscription. The subscription contains a locally-redundant storage (LRS) account named storage1 that is deployed to the US East Azure region and has a Microsoft.Storage service endpoint. You set Redundancy for storage1 to Read-access geo-redundant storage (RA-GRS). You need to ensure that the contents of storage1 will be accessible by using a service endpoint in a paired region. The solution must minimize administrative effort. What should you do first?

  1. Create an object replication rule for storage.
  2. Delete the existing service endpoint.
  3. From storage1, select Secure transfer required.
  4. Create a service endpoint policy. Correct Answer

Community Votes

D
66%
A
17%
B
17%

66% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tested: applying a service endpoint policy upgrades the Azure Storage service endpoint scope from regional to global; the trap is assuming RA-GRS replication, or deleting/recreating the endpoint, is what exposes the paired region.

A subnet's Microsoft.Storage service endpoint is region-scoped by default, so storage1's RA-GRS secondary endpoints in the paired region stay unreachable until a service endpoint policy is applied. This AZ-700 page confirms answer D — creating the service endpoint policy is the first, lowest-effort step.

Picking A (object replication) because the scenario mentions a paired region; object replication copies blob data between accounts and adds rules and prerequisites, but it never changes what the subnet's service endpoint can reach.

Community Discussion (7 comments)

NK203 👍 5 Selected: D
When Service Endpoint policies are applied on a subnet, the Azure Storage Service Endpoint scope gets upgraded from regional to global. This process means that all the traffic to Azure Storage is secured over service endpoint thereafter. The Service endpoint policies are also applicable globally. Any storage accounts that aren't explicitly allowed are denied access. https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-overview
xRiot007 👍 1
D - set a policy to control to what can the VNet have access when using the service point. Ref: https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-overview
a250fb0 👍 1 Selected: B
When you switch the redundancy of a storage account from Locally Redundant Storage (LRS) to Read-Access Geo-Redundant Storage (RA-GRS), the storage account gains a secondary endpoint in the paired region. However, existing service endpoints are tied to the primary region only, and they do not automatically support access to the secondary endpoint in the paired region. D. Create a service endpoint policy: Service endpoint policies are used to restrict which storage accounts can be accessed via a service endpoint, but they do not enable access to paired regions.
bobothewiseman 👍 1 Selected: D
My final answer is D. Create a service endpoint policy.
bobothewiseman 👍 1 Selected: B
I will go with B! When you enable Read-access geo-redundant storage (RA-GRS) for your storage account, the data is replicated to a secondary region (the paired region) to provide read access in case of a regional outage. However, service endpoints are tied to the original region where they were created and do not automatically update to include access from the paired region
alexastein 👍 2 Selected: D
https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-overview
sismer 👍 2 Selected: A
To ensure that the contents of your storage account (storage1) will be accessible by using a service endpoint in a paired region with minimal administrative effort, you should: A. Create an object replication rule for storage. This will allow you to replicate the contents of storage1 to another storage account in the paired region, ensuring accessibility through a service endpoint in that region.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft's service endpoint policy documentation states that once a policy is applied on a subnet, the Azure Storage service endpoint scope is upgraded from regional to global, after which traffic to Azure Storage is secured over service endpoints wherever the account lives. That is exactly the blocker in this scenario: the subnet in US East has a Microsoft.Storage endpoint, but a regional endpoint only covers storage accounts in the VNet's own region, even though RA-GRS has given storage1 read-only secondary endpoints in its paired region. Creating a service endpoint policy (and allowing storage1 in it) is therefore the action that makes the paired-region content reachable, and it is also the minimum-effort option — no data copy, no endpoint teardown, no per-region endpoint plumbing. The word "first" in the question points at this scope-changing step rather than at anything done afterwards. Because the question asks what to do first and the scope upgrade happens the moment a policy is attached, D is the only option that directly satisfies the requirement.

Why the Other Options Are Wrong

A (object replication) is a data-copy feature that replicates block blobs from one storage account to another, typically in the paired region; it requires source and destination accounts, versioning, and replication rules, which is a lot of administrative effort and does not extend the service endpoint at all. B (delete the existing service endpoint) is the opposite of what is needed: removing the endpoint strips storage1 of its current service-endpoint access, and recreating the same endpoint simply returns it to regional scope, so the paired region remains unreachable. C (Secure transfer required) only enforces HTTPS/TLS for requests to the account; it is a transport-security setting with no bearing on which regions the service endpoint can address. None of A, B, or C changes the regional-to-global scope of the Microsoft.Storage endpoint, which is the actual requirement.

Community Comment Notes

NK203 captures the decisive doc behavior verbatim — that when policies are applied on a subnet, "the Azure Storage Service Endpoint scope gets upgraded from regional to global" — which is why the vote count of 67 for D matches the official overview page. alexastein and xRiot007 both cite the service endpoint policies overview as the justification for D, and xRiot007 frames it as using a policy to control what the VNet may reach over the endpoint. sismer argues for A, reasoning that object replication would place the contents in a paired region, but that answer moves data rather than making the existing endpoint global, so it misses the requirement. bobothewiseman first settled on D, then switched to B on the premise that "service endpoints are tied to the original region" — that premise is correct, but deleting the endpoint does not widen its scope, so the B rationale collapses.

Official Reference

Exam Strategy

When AZ-700 asks how a subnet reaches storage in a paired region over a service endpoint, look for the feature that changes the endpoint's scope, not the one that moves data. Also treat "what should you do first" and "minimize administrative effort" as filters: policy creation beats replication rules, and deleting/recreating an endpoint never changes its regional scope.

Frequently Asked Questions

Why doesn't RA-GRS alone make storage1 reachable from a paired region over a service endpoint?

RA-GRS adds read-only secondary endpoints for storage1 in its paired region, but the subnet's Microsoft.Storage service endpoint stays region-scoped until a service endpoint policy is applied to that subnet.

Why is deleting the existing service endpoint (option B) not the fix?

Deleting the endpoint drops storage1's current service-endpoint access and does not change the endpoint's regional scope; recreating it returns the same regional endpoint, leaving the paired region unreachable.

Related Analysis

Practice All AZ-700 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-700 Practice Test →

← Back to AZ-700 Study Guide