Soru

Zorluk: OrtaAzure Files Backup and Restore

You manage an Azure environment that contains a Premium storage account named sa-hr-files in the East US region. The storage account hosts an SMB file share named employeerecords. The firewall of sa-hr-files is enabled and configured to allow access only from selected virtual networks and IP addresses.

You have a Recovery Services vault named rsv-hr-backup in the East US region.

An administrator named Admin1, who has the Backup Operator role on rsv-hr-backup and the Contributor role on sa-hr-files, attempts to configure Azure Backup for the employeerecords file share. During configuration, the vault cannot discover the file share.

What configuration change should you make to ensure that the file share can be successfully backed up?

  1. A
    Assign the Storage File Data Privileged Contributor role on the storage account to the system-assigned managed identity of the Recovery Services vault.
  2. Enable the option to allow trusted Microsoft services to access the storage account in the firewall settings of the storage account.Cevap
  3. C
    Assign the Owner role on the storage account to Admin1.
  4. D
    Configure a virtual network service endpoint for Azure Backup on the subnet associated with the Recovery Services vault.

Cevap

Enable the option to allow trusted Microsoft services to access the storage account in the firewall settings of the storage account.
Enabling the option to allow trusted Microsoft services to access the storage account is correct because Azure Backup is recognized as a trusted Microsoft service. When the storage account firewall is enabled, this exception is required to allow the vault to communicate with the storage account and discover or back up the SMB file share.

Adım Adım Çözüm

1
Analyze the network configuration of the storage account.
The Premium storage account has its firewall enabled, restricting access to only selected virtual networks and IP addresses, which blocks external services like Azure Backup by default.
Before configuring backup, the network access path between the Recovery Services Vault and the storage account must be validated.
2
Identify the bypass setting for trusted Microsoft services.
Enabling the 'Allow trusted Microsoft services to access this storage account' exception allows Azure Backup to bypass the firewall rules.
Azure Backup is a trusted Microsoft service that operates at the control plane to coordinate snapshot-based backups for Azure Files.
3
Verify administrator permissions.
Admin1 has Backup Operator on the vault and Contributor on the storage account, which are sufficient control-plane permissions for registering the storage account.
No RBAC changes are needed because the failure is network-based rather than permission-based.

Anahtar Kavram

To back up Azure File shares in a firewalled storage account, you must configure the storage account firewall to allow trusted Microsoft services.
Tahmini Süre:1m 30s
Bu soruyu puanla