Storage Blob Data Contributor Role: Access and Permissions for Azure Container | Exam DP-203

Access and Permissions for Storage Blob Data Contributor Role at Container Level

Question

You have been assigned the Storage Blob Data Contributor role at a container level.

Here are two statements regarding this: You have been granted write, read, and delete access to all blobs in that container. You can view a blob within Azure portal. Which of the above-given statements are true?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

Correct Answer: A

If the Storage Blob Data Contributor role is assigned to a user at the container level, titled sample-container, and the user is granted write, read, and delete permission to the blobs present in that specific container.

But Storage Blob Data Contributor role itself does not provide enough permission to navigate to reach the blob through the Azure portal for view purposes.

Extra permission is needed in order to perform a navigation through the Azure portal and see the additional resources which are available or visible there.

Option A is correct.

Storage Blob Data Contributor role at container level grants the write, read, and delete permission for all the blobs in that container.

Option B is incorrect.

With only the Storage Blob Data Contributor role, you can't perform navigation to the blobs via Azure portal.

Therefore, statement a is correct while statement b is incorrect.

Option C is incorrect.

Statement b is incorrect.

Option D is incorrect.

Statement a is correct while statement b is incorrect.

To know more about assigning Azure roles for data access, please visit the below-given link:

The correct answer is A. Only statement A is true.

As a Storage Blob Data Contributor, you have write, read, and delete access to all blobs in the container level to which the role is assigned. Therefore, statement A is true.

However, the Storage Blob Data Contributor role does not grant you the permission to view blobs within the Azure portal. The Storage Blob Data Reader role is required to view blobs within the Azure portal. Therefore, statement B is false.

In summary, as a Storage Blob Data Contributor, you have write, read, and delete access to all blobs in the container level, but you cannot view blobs within the Azure portal.