You manage a Premium storage account named stcorpfiles01 in the East US 2 region. The storage account hosts an SMB file share named sharesmbcore and has its firewall configured to restrict access to selected virtual networks. You configure a Recovery Services vault named rsv-corp-backup in the same region to back up the file share. When you attempt to configure the backup, the operation fails because the vault cannot access the storage account. Which configuration is required on the storage account to resolve this issue?
- Enable the 'Allow trusted Microsoft services to access this storage account' bypass option under the Firewalls and virtual networks settings.Cevap
- BAssign the Backup Operator role to the Recovery Services vault's system-assigned managed identity on the storage account.
- CAdd the public IP address of the Recovery Services vault to the allowed IP address ranges in the storage account firewall rules.
- DAssign the Storage File Data Privileged Contributor role to the user account performing the backup configuration.
Cevap
Enable the 'Allow trusted Microsoft services to access this storage account' bypass option under the Firewalls and virtual networks settings.
The correct option is to enable the 'Allow trusted Microsoft services to access this storage account' bypass option. When an Azure Storage account firewall is enabled, Azure Backup requires this bypass to interact with the storage account and take the snapshots required for backing up the file shares.
Adım Adım Çözüm
Anahtar Kavram
Azure Files Backup and Restore
Tahmini Süre:1m 30s