nerdexam
Microsoft

AZ-500 · Question #183

Drag and Drop Question Your network contains an on-premises Active Directory domain named contoso.com. The domain contains a user named User1. You have an Azure subscription that is linked to an…

The correct answer is Implement Azure AD Connect.; Enable Active Directory Domain Services (AD DS) authentication on storage1.; Assign share-level permissions for share1. The correct sequence begins with implementing Azure AD Connect to synchronize on-premises AD identities (including User1) to Azure AD, bridging the gap between the on-premises domain and the Azure AD tenant. Next, AD DS authentication must be enabled on storage1 to allow the…

Submitted by khalil_dz· Mar 6, 2026Implement and manage storage - Configure Azure Files authentication and authorization using on-premises Active Directory Domain Services (AZ-104 / AZ-305)

Question

Drag and Drop Question Your network contains an on-premises Active Directory domain named contoso.com. The domain contains a user named User1. You have an Azure subscription that is linked to an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains an Azure Storage account named storage1. Storage1 contains an Azure file share named share1. Currently, the domain and the tenant are not integrated. You need to ensure that User1 can access share1 by using his domain credentials. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Answer:

Exhibit

AZ-500 question #183 exhibit

Answer Area

Drag items

Create a private link to storage1.Enable Active Directory Domain Services (AD DS) authentication on storage1.Implement Azure AD Connect.Create a service endpoint to storage1.Assign share-level permissions for share1.

Correct arrangement

  • Implement Azure AD Connect.
  • Enable Active Directory Domain Services (AD DS) authentication on storage1.
  • Assign share-level permissions for share1.

Explanation

The correct sequence begins with implementing Azure AD Connect to synchronize on-premises AD identities (including User1) to Azure AD, bridging the gap between the on-premises domain and the Azure AD tenant. Next, AD DS authentication must be enabled on storage1 to allow the storage account to recognize and authenticate domain-joined identities using Kerberos tickets. Finally, share-level permissions must be assigned for share1 so that User1 has the appropriate RBAC role (e.g., Storage File Data SMB Share Reader/Contributor) to access the file share with their domain credentials.

Topics

#Azure Files Authentication#Active Directory Domain Services#Azure AD Connect#Hybrid Identity

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice