Soru

Zorluk: Çok zorAzure Files Backup and Restore

You manage an Azure subscription that contains a Premium storage account named sa-corp-files in the East US 2 region. The storage account hosts two file shares: an SMB file share named records-smb and an NFS file share named records-nfs. The firewall of sa-corp-files is enabled and configured to allow traffic only from selected virtual networks and IP addresses. The option 'Allow trusted Microsoft services to access this storage account' is currently disabled. You have a Recovery Services vault named rsv-corp-backup in the East US 2 region. Your user account is assigned the Backup Operator role at the resource group level containing all these resources. You need to configure a backup policy in rsv-corp-backup to back up the supported file shares in sa-corp-files while ensuring the minimum administrative permissions are assigned. Which of the following actions should you perform?

  1. Enable 'Allow trusted Microsoft services to access this storage account' on the firewall of sa-corp-files, assign the Storage Account Contributor role to your user account on sa-corp-files, and configure backup for the records-smb file share only.Cevap
  2. B
    Assign the Storage Account Contributor role to your user account on sa-corp-files, and configure backup for the records-smb file share only without modifying the firewall settings of sa-corp-files.
  3. C
    Enable 'Allow trusted Microsoft services to access this storage account' on the firewall of sa-corp-files, and configure backup for both the records-smb and records-nfs file shares using your existing Backup Operator role permissions.
  4. D
    Enable 'Allow trusted Microsoft services to access this storage account' on the firewall of sa-corp-files, assign the Storage Account Contributor role to your user account on sa-corp-files, and configure backup for both the records-smb and records-nfs file shares.

Cevap

Enable 'Allow trusted Microsoft services to access this storage account' on the firewall of the storage account, assign the Storage Account Contributor role to your user account on the storage account, and configure backup for the SMB file share only.
To back up an Azure file share using Azure Backup, several conditions must be met: 1. Only SMB file shares are supported; NFS file shares cannot be backed up using this service. 2. When the storage account firewall is enabled, you must enable the 'Allow trusted Microsoft services to access this storage account' setting to permit Azure Backup access. 3. The administrator configuring the backup needs write permissions on the storage account (such as Storage Account Contributor or Contributor) to register the storage account and manage snapshots, which are not provided by the Backup Operator role.

Adım Adım Çözüm

1
Identify file share protocol compatibility for Azure Backup.
Only the SMB file share (records-smb) can be backed up using Azure Backup; the NFS file share (records-nfs) is not supported.
Azure Files backup via Recovery Services vaults supports only SMB file shares.
2
Configure storage account firewall settings.
Enable 'Allow trusted Microsoft services to access this storage account' bypass on the storage account firewall.
This allows the Azure Backup service to securely access the firewall-protected storage account to perform backup operations.
3
Verify and assign required RBAC permissions.
Assign the Storage Account Contributor (or Contributor) role to the user account on the storage account.
The Backup Operator role only grants permissions on the Recovery Services vault, but configuring Azure Files backup requires write permissions (such as creating share snapshots) on the storage account itself.

Anahtar Kavram

Azure Files backup compatibility, storage firewall bypass, and RBAC requirements
Bu soruyu puanla