Azure Files Datastore Authorization Method
You manage an Azure Machine Learning Workspace named Workspase1 and an Azure Files share named Share1. You plan to create an Azure Files datastore in Workspace1 to target Share1. You need to configure permanent access to Share1 from the Azure Files datastore. Which authorization method should you use?
Community Votes
56% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between temporary SAS tokens and permanent keys; the trap is selecting a SAS type which expires, whereas 'permanent' implies a key.
Configure Azure Machine Learning datastores with permanent access using storage account keys. The community consensus favors the secondary access key for long-term, non-expiring credentials in this specific scenario.
Candidates often choose Account SAS or Service SAS because they understand token-based security, failing to realize that SAS tokens have expiration limits and are not suitable for 'permanent' datastore configurations.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The question specifies the need for 'permanent access.' In Azure Storage, access keys (primary or secondary) do not expire unless manually rotated, making them the standard choice for persistent connections like ML Workspaces. Using the secondary key is a best practice for security isolation.Why the Other Options Are Wrong
SAS keys (Account or Service) are inherently temporary and subject to expiration policies, even if extended via policy, they are not truly permanent in the same way keys are. Anonymous access is insecure and typically disabled by default for production workloads requiring managed workspace integration.Community Comment Notes
Comment [1] correctly identifies the use of storage account keys for long-term access without renewal. Comment [3] highlights the limitation of User Delegation SAS (7-day max), reinforcing why SAS options are unsuitable for permanent setups. The high vote count for A confirms this is the expected certification answer.Official Reference
Exam Strategy
When 'permanent' or 'persistent' is mentioned regarding Azure Storage authentication in exam questions, prioritize Access Keys over SAS tokens. Remember that SAS tokens are designed for limited-time, scoped access.