Soru

Zorluk: OrtaAzure Files Backup and Restore

A company named Contoso, Ltd. plans to implement backups for a critical file share. You are configuring a backup policy in a Recovery Services vault named `rsv-contoso-sea` in the Southeast Asia region. The target file share is an SMB file share named `records-smb` hosted within a Premium storage account named `sapremrecords`. The network configuration for `sapremrecords` is configured to 'Enabled from selected networks' to meet security compliance.

During the configuration of the backup, the vault is unable to discover the file share inside the storage account.

Which of the following actions should you perform to resolve this issue?

  1. A
    Configure the firewall of the storage account to allow inbound traffic from the public IP address of the Recovery Services vault.
  2. B
    Assign the Storage File Data Privileged Reader role to the Recovery Services vault's system-assigned managed identity on the storage account.
  3. Configure the firewalls and virtual networks settings of the storage account to allow trusted Microsoft services to access the storage account.Cevap
  4. D
    Assign the Backup Operator role to the storage account's resource group to grant the vault permission to write snapshots.

Cevap

Configure the firewalls and virtual networks settings of the storage account to allow trusted Microsoft services to access the storage account.
The correct action is to allow trusted Microsoft services to access the storage account. When a storage account firewall is configured to restrict access to selected networks, Azure Backup (which is a trusted Microsoft service) cannot access it unless the exception for trusted services is enabled in the firewall configuration.

Adım Adım Çözüm

1
Identify the cause of the discovery failure.
The storage account network configuration is restricting access to selected networks, preventing the Recovery Services vault from communicating with it.
By default, enabling the storage firewall blocks external services, including Azure Backup, from registering or discovering shares.
2
Select the correct mitigation strategy.
Determine that Azure Backup is classified as a trusted Microsoft service.
Using the built-in trusted service exception is the secure and supported method to bypass the firewall for backup operations.
3
Enable the trusted service bypass on the storage account.
Access is granted to the backup service, allowing the vault to discover and configure backup for the SMB file share.
Checking the option to allow trusted Microsoft services permits the vault to register the storage account and execute backup jobs.

Anahtar Kavram

To configure backups for Azure File shares hosted in a storage account with firewall restrictions, you must enable the trusted Microsoft services bypass in the storage account's network settings.
Bu soruyu puanla