You manage a data processing application that receives requests from an Azure Storage queue.
You need to manage access to the queue. You have the following requirements:
Provide other applications access to the Azure queue.
Ensure that you can revoke access to the queue without having to regenerate the storage account keys.
Specify access at the queue level and not at the storage account level.
Which type of shared access signature (SAS) should you use?
A service SAS is secured with the storage account key. A service SAS delegates access to a resource in only one of the Azure Storage services: Blob storage, Queue storage, Table storage, or Azure Files.
Stored access policies give you the option to revoke permissions for a service SAS without having to regenerate the storage account keys.
https://docs.microsoft.com/en-us/azure/storage/common/storage-sas-overview
Currently there are no comments in this discussion, be the first to comment!