AZ-140 · Question #24
You have a Azure Virtual Desktop host pool named Pool1 and an Azure Storage account named Storage1. Storage1 stores FSLogix profile containers in a share folder named share1. You create a new group…
The correct answer is C. the Modify NTFS permissions for share1 F. the Storage File Data SMB Share Contributor role for storage1. You give the user Modify AND remove authenticated users and builtin/users, so that only one user has access to each profile container. Admins continue to have access if that was given correctly…
Question
You have a Azure Virtual Desktop host pool named Pool1 and an Azure Storage account named Storage1. Storage1 stores FSLogix profile containers in a share folder named share1. You create a new group named Group1. You provide Group1 with permission to sign in to Pool1. You need to ensure that the members of Group1 can store the FSLogix profile containers in share1. The solution must use the principle of least privilege. Which two privileges should you assign to Group1? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- Athe Storage Blob Data Contributor role for storage1
- Bthe List folder / read data NTFS permissions for share1
- Cthe Modify NTFS permissions for share1
- Dthe Storage File Data SMB Share Reader role for storage1
- Ethe Storage File Data SMB Share Elevated Contributor role for storage1
- Fthe Storage File Data SMB Share Contributor role for storage1
How the community answered
(41 responses)- B5% (2)
- C83% (34)
- D2% (1)
- E10% (4)
Explanation
You give the user Modify AND remove authenticated users and builtin/users, so that only one user has access to each profile container. Admins continue to have access if that was given correctly. https://docs.microsoft.com/en-us/azure/storage/files/storage-files-identity-ad-ds-configure- permissions#azure-rbac-permissions
Topics
Community Discussion
No community discussion yet for this question.