Pluralsight Hands-On Lab — Azure Storage Security
Pluralsight Hands-On Lab — Storage
| Platform | Pluralsight |
|---|---|
| Category | Azure Storage Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Azure Cloud Shell (Bash) |
| Completed | 2026 |
A user delegation SAS is a more secure alternative to a standard Shared Access Signature because it is backed by an Azure Active Directory identity rather than a storage account key. This means access can be revoked by revoking the delegation keys rather than rotating the account key. In this lab, I uploaded a file to a private blob container, generated a user delegation SAS using Azure CLI with scoped permissions and a time-bound expiry, validated access via the generated URL, and then revoked the SAS by invalidating all user delegation keys on the storage account.
az storage blob generate-sas --account-name <account> \ --container-name container1 \ --name <filename> \ --permissions acdrw \ --expiry <YYYY-MM-DD> \ --auth-mode login \ --as-user \ --full-uri
az storage account revoke-delegation-keys --name <account> --resource-group <rg>