Azure Files Datastore Authorization Method

You manage an Azure Machine Learning Workspace named Workspase1 and an Azure Files share named Share1. You plan to create an Azure Files datastore in Workspace1 to target Share1. You need to configure permanent access to Share1 from the Azure Files datastore. Which authorization method should you use?

  1. Secondary access key Source Reference Answer
  2. Anonymous access
  3. Account SAS key
  4. Service SAS key

Community Votes

A
56%
C
22%
D
22%

56% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between temporary SAS tokens and permanent keys; the trap is selecting a SAS type which expires, whereas 'permanent' implies a key.

Configure Azure Machine Learning datastores with permanent access using storage account keys. The community consensus favors the secondary access key for long-term, non-expiring credentials in this specific scenario.

Candidates often choose Account SAS or Service SAS because they understand token-based security, failing to realize that SAS tokens have expiration limits and are not suitable for 'permanent' datastore configurations.

Community Discussion (4 comments)

jl420 👍 3 Selected: A
The correct answer is: A. Secondary access key Explanation: To configure permanent access to an Azure Files share from an Azure Files datastore in an Azure Machine Learning workspace, you generally use the primary or secondary access key of the Azure Storage account that contains the file share. This provides long-term access without the need to renew credentials, as the access keys remain valid until they are manually regenerated. Why the Other Options Don’t Meet the Goal: B. Anonymous access: Azure Files does not support anonymous access. Access requires authentication through either account keys, SAS tokens, or identity-based methods. C. Account SAS key: While an Account SAS key provides scoped access to storage resources, it is typically short-lived and must be regenerated periodically, making it unsuitable for permanent access. D. Service SAS key: Similar to the Account SAS, a Service SAS key is also short-lived and used for temporary access to specific resources. It must be renewed, so it does not meet the requirement for permanent access.
Arvindu89 👍 2 Selected: D
Account SAS and Service SAS are both types of Shared Access Signatures in Azure, but they differ in terms of scope and control. Account SAS: Grants access to resources within a storage account, such as blobs, files, queues, or tables. Offers broader permissions and can cover multiple services within the storage account. Allows you to specify permissions, including read, write, delete, list, and more for the entire account. Service SAS: Grants access to specific resources within a single service, like a specific blob or file share. Offers more fine-grained control compared to Account SAS. Allows you to specify permissions and set constraints, like IP ranges, protocols, and expiration times, but only for the specified resource.
kfgg 👍 2 Selected: A
A user delegation SAS has a maximum expiry interval of 7 days, regardless of the SAS expiration policy. I think answer should be A? https://learn.microsoft.com/en-us/azure/storage/common/sas-expiration-policy?tabs=azure-portal#configure-a-sas-expiration-policy https://learn.microsoft.com/en-us/azure/storage/common/storage-account-keys-manage?tabs=azure-portal
jefimija 👍 2 Selected: C
I never came across service sas key, only account sas key

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The question specifies the need for 'permanent access.' In Azure Storage, access keys (primary or secondary) do not expire unless manually rotated, making them the standard choice for persistent connections like ML Workspaces. Using the secondary key is a best practice for security isolation.

Why the Other Options Are Wrong

SAS keys (Account or Service) are inherently temporary and subject to expiration policies, even if extended via policy, they are not truly permanent in the same way keys are. Anonymous access is insecure and typically disabled by default for production workloads requiring managed workspace integration.

Community Comment Notes

Comment [1] correctly identifies the use of storage account keys for long-term access without renewal. Comment [3] highlights the limitation of User Delegation SAS (7-day max), reinforcing why SAS options are unsuitable for permanent setups. The high vote count for A confirms this is the expected certification answer.

Official Reference

Exam Strategy

When 'permanent' or 'persistent' is mentioned regarding Azure Storage authentication in exam questions, prioritize Access Keys over SAS tokens. Remember that SAS tokens are designed for limited-time, scoped access.

Related Analysis

← Back to DP-100 Study Guide