What you’ll be able to do
- Explain storage account, container, and blob.
- Keep anonymous blob access disabled.
- Verify upload and authorized download without distributing account keys.
Get the idea
Three levels of organization
A storage account provides the service boundary. A container groups blobs inside the account. A blob holds an individual object, such as a document or image. A container is not a resource group.
A URL is not authorization
A blob can have an address while remaining private. Access can be authorized through Entra ID, a shared access signature, or other permitted methods. Do not paste a signed URL into a public repository or use a sensitive file in a lab.
Separate control and data permissions
Permission to create or configure a storage account does not necessarily grant blob-data access. If uploads fail, inspect the data role and network settings before enabling public access or sharing account keys.
Try it yourself
- Create a StorageV2 account in rg-learningazure through the portal. Choose a globally unique lowercase name, Standard performance, and LRS for the lab. Review price and region.
- Keep anonymous blob access disabled. If your organization requires particular networking settings, use those rather than bypassing them.
- Confirm your account has the appropriate blob-data role. Open Containers and create a container named practice with private access.
- Create a local file named hello.txt containing only a short greeting. Check the portal authentication method and switch to Microsoft Entra user account if it is using an account key, then upload the file.
- Download it through the authorized session and compare its content. Open the unsigned blob URL in a private browser window: anonymous reading should be denied.
Finish the lab
Delete hello.txt and the practice container, then remove the lab storage account if no longer needed. Storage capacity, requests, and transfer may incur charges. Do not delete shared or production data.
Quick knowledge check
An upload returns an authorization error. Should you make the container public?
Reveal the explanation
No. Public access does not fix the intended private authorization model. Check identity, data permissions, propagation delay, and network restrictions.
Take this with you
Use identity and data permissions to solve access problems; keep private content private.
Go deeper
AI-assisted lesson · Reference links checked October 3, 2026. Exercises are teaching examples; they have not been executed against your Azure subscription.