# Storage Accounts, Tiers and Redundancy — Azure

Source: https://www.skillbyai.com/en/azure/d-storage

> Choose blob access tiers and redundancy options for cost and durability.

## One account, four services

An Azure **storage account** provides **Blob** storage (objects such as images, backups and data-lake files), **Azure Files** (SMB/NFS file shares), **Queue** storage (simple message queues) and **Table** storage (a key-value store). Blobs have **access tiers**: **Hot** for frequent access, **Cool** and **Cold** for less frequent access at lower storage cost but higher read cost and minimum retention periods, and **Archive**, which is offline and must be rehydrated (taking hours) before reading. **Lifecycle management** rules move blobs between tiers automatically. **Redundancy** decides how many copies exist and where: **LRS** (three copies in one datacentre), **ZRS** (across three zones), **GRS** (LRS plus an asynchronous copy in the paired region), **GZRS** (ZRS plus the secondary region), with **RA-** variants that allow reads from the secondary.

## Copies across zones and regions

Each redundancy option adds copies further away: inside a datacentre, across zones, then to a second region.

![Left, a single box holding three small copies; middle, three zone boxes each holding a copy; right, a second region box receiving a dashed replication arrow.](assets/figures/azure/section-5-map.svg) — Figure 5.1 — LRS, ZRS and geo-redundant replication.

## A lifecycle policy that ages logs to cheaper tiers

Saved as `policy.json` and applied with `az storage account management-policy create`.

```json
{
  "rules": [
    {
      "name": "age-logs",
      "enabled": true,
      "type": "Lifecycle",
      "definition": {
        "filters": { "blobTypes": ["blockBlob"], "prefixMatch": ["logs/"] },
        "actions": {
          "baseBlob": {
            "tierToCool":    { "daysAfterModificationGreaterThan": 30 },
            "tierToArchive": { "daysAfterModificationGreaterThan": 180 },
            "delete":        { "daysAfterModificationGreaterThan": 730 }
          }
        }
      }
    }
  ]
}
```

## Keep blobs private

Disable anonymous blob access on the account and share files with **user delegation SAS** tokens (signed with Entra credentials and short-lived) or through a CDN with private origin access. Long-lived account-key SAS URLs pasted into chats are a common leak.

**Quiz:** A storage account must survive the loss of one availability zone but data must stay in one region. Which redundancy option fits?

- [x] ZRS
- [ ] LRS
- [ ] GRS
- [ ] RA-GRS

*Answer:* ZRS. ZRS keeps synchronous copies in three zones of the same region.
