StudyToCert

All certifications / SC-500 / Lessons

Microsoft Certified: Cloud and AI Security Engineer Associate (replaces Azure Security Engineer Associate / AZ-500) SC-500 · Domain 2: Secure storage, databases, and networking

Storage authorization: Entra ID with data-plane RBAC, account keys, disabling Shared Key, key rotation

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Every request to read or write data in Azure Storage (blobs, files, queues, tables) must be authorized. There are several ways, and the exam wants you to rank them. The strongest is Microsoft Entra ID authorization: the caller presents an OAuth 2.0 token for a user, group, service principal or managed identity, and Azure checks their data-plane RBAC roles. No shared secret exists to leak, access is tied to identity and can be revoked, and every request is attributable in logs.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study plan