How Does WebApp1 Read and Write to storage1 with Its Managed Identity?

Plan and implement identities for applications and Azure workloads
Answer Correct answer: C — assign the WebApp1 system-assigned managed identity a data-plane role such as Storage Blob Data Contributor through the storage1 Access control (IAM) settings.

You have an Azure subscription that contains a storage account named storage1 and a web app named WebApp1. WebApp1 uses a system-assigned managed identity. You need to ensure that WebApp1 can read and write files to storage1 by using the system-assigned managed identity. What should you configure for storage1 in the Azure portal?

  1. data protection
  2. a shared access signature (SAS)
  3. the Access control (IAM) settings Correct Answer
  4. the File share settings
  5. access keys

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests whether you know that Azure RBAC role assignments on the storage account (IAM) authorize a managed identity, while the trap is reaching for storage access keys or a SAS token that keep the app on shared-key authentication instead of identity-based access.

Granting a web app's system-assigned managed identity read/write access to an Azure storage account is done from the storage account's Access control (IAM) blade, where the identity receives a data-plane RBAC role such as Storage Blob Data Contributor. This page confirms option C and explains why SAS tokens, access keys, and file share settings do not satisfy the managed identity requirement.

Learners pick a shared access signature (SAS) or access keys because they still treat storage authorization as a secret handed to the app, ignoring that a system-assigned managed identity must be granted a data-plane RBAC role on the storage account itself.

Community Discussion (3 comments)

RucasII 👍 1
In the Azure portal, go into your storage account to grant your web app access. Select Access control (IAM) in the left pane, and then select Role assignments. You'll see a list of who has access to the storage account. Now you want to add a role assignment to a robot, the app service that needs access to the storage account. Select Add > Add role assignment to open the Add role assignment page. https://learn.microsoft.com/en-us/entra/identity-platform/multi-service-web-app-access-storage?tabs=azure-portal%2Cprogramming-language-csharp#grant-access-to-the-storage-account
ANiMOSiTYOP 👍 4 Selected: C
C is the correct answer because access to resources in Azure is dealt with through Azure Role-Based Access Control (RBAC). This allows fine-grained access management for Azure. System-assigned managed identities can be assigned roles through IAM settings of a resource, granting them permissions to perform certain actions. To access files in Azure Storage, you would assign the Storage Blob Data Reader role for read access and the Storage Blob Data Contributor role for write access to the managed identity in the IAM settings. Here's the Microsoft documentation needed about granting access using RBAC and Azure AD identities: https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal
Wazery 👍 2
Access control (IAM) settings in Azure allow you to manage access to various resources within your Azure subscription. If you want to ensure that the WebApp1 web app can read and write files in storage1, you must grant the web app the appropriate permissions on the storage1 storage account. By configuring access control (IAM) for the storage account "storage1", you can assign the necessary permissions (such as "Storage Blob Data Contributor" or "Storage Blob Data Reader") to the web app's managed identity to access the Blob services can access to read and write files.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The question fixes the authentication method: WebApp1 must use its system-assigned managed identity, so authorization has to flow through Microsoft Entra ID and Azure RBAC, and the portal surface for RBAC on a storage account is Access control (IAM). You assign the WebApp1 identity a data-plane role such as Storage Blob Data Contributor (or Storage File Data SMB Share Contributor for Azure Files) as a role assignment on storage1. As ANiMOSiTYOP explained, "access to resources in Azure is dealt with through Azure Role-Based Access Control (RBAC)", and system-assigned managed identities receive roles through the resource's IAM settings. RucasII described the exact click path, noting you "Select Add > Add role assignment" from the storage account's IAM pane to grant the App Service identity access. Because the identity is already created by enabling it on WebApp1, only the role assignment step remains, which is precisely what option C configures.

Why the Other Options Are Wrong

Data protection settings control durability and retention features such as soft delete, versioning, and immutability policies; they say nothing about who may read or write data. A shared access signature is a signed, time-bound token that authorizes the request itself rather than the app's managed identity, and it forces you to store and rotate a secret in the app, defeating the purpose of using an identity. File share settings expose share-level properties such as quotas and snapshots, not identity permissions. Access keys enable shared-key authorization, which bypasses Microsoft Entra ID entirely and again requires embedding and rotating a secret instead of using the managed identity. Only IAM role assignments delegate permissions to a service principal representing the managed identity.

Community Comment Notes

Every recorded learner selected C, and the comments consistently reason from RBAC rather than from storage keys or SAS. Wazery framed it as needing to "grant the web app the appropriate permissions on the storage1 storage account", which maps directly to a role assignment. RucasII supplied the operational walkthrough of the IAM pane, which is the same evidence an exam-taker can rely on when two options both sound like "permissions". No comment defends a SAS or access key, so the community consensus and the technical analysis agree on C. One nuance worth remembering: the role you pick must be a data-plane role, because management-plane roles alone will not let the identity read blob or file contents.

Exam Strategy

When a stem says "using the system-assigned managed identity", eliminate every option that is a key, secret, connection string, or signed token, because those represent shared-key or delegated authentication and never consume the identity. The remaining answer is a role assignment on the target resource, reached through Access control (IAM). Then sanity-check that the role you would choose is a data-plane role (Storage Blob Data Contributor) rather than a management-plane role (Contributor), since this is the most common secondary trap on SC-300 storage questions.

Official Reference

Exam Strategy

When a stem specifies "using the system-assigned managed identity", strike out every option that is a key, secret, SAS token, or connection string, because those are shared-key or delegated auth paths that never consume the identity. What remains is a role assignment on the target resource, configured through Access control (IAM). Finally verify you would assign a data-plane role such as Storage Blob Data Contributor rather than a management-plane role like Contributor.

Frequently Asked Questions

Why is a shared access signature (SAS) wrong if WebApp1 needs to read and write files?

A SAS is a signed, time-limited token that must be stored and rotated inside the app, and it authorizes the request itself rather than the app's system-assigned managed identity, so it never satisfies identity-based access.

Which role should the managed identity get on storage1 for read and write?

For blob data, assign Storage Blob Data Contributor (Storage Blob Data Reader for read-only). For Azure Files, assign Storage File Data SMB Share Contributor via the same Access control (IAM) blade.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide