Storage account network rules may allow broad access

Limit public network access to the clients that need the storage account, and review allowed sources and service exceptions.

Description

An Azure Storage public endpoint open to every network allows clients outside the workload's intended network to attempt data access. In Ansible, network_acls.default_action: Allow leaves that public endpoint unrestricted by the firewall's default policy. Even with Deny, overly broad address ranges or service exceptions can allow more connections than intended.

Azure gives public_network_access precedence over the firewall's default action. When disabling public access, also review existing trusted-service and resource-instance exceptions. Permission to connect through the network boundary is separate from permission to read or write data. An open public endpoint does not by itself grant anonymous access.

Potential impact

  • Broad network access can allow leaked credentials or excessive data permissions to be abused from networks that have no business need to connect.
  • Protecting sensitive data requires both restricted client connection paths and appropriate data permissions.

Remediation

  1. If the public endpoint is needed, set network_acls.default_action to Deny and allow only required public IPv4 addresses or virtual networks. Keep resource-instance rules and bypass exceptions limited to their required purposes.
  2. If only private connectivity is needed, configure private endpoints for the storage services in use and their DNS before applying public_network_access: Disabled. Creating a private endpoint does not block public access by itself. Review any retained service and resource-instance exceptions.
  3. Use the client's actual public source address in IP rules. IP rules do not apply to requests from the same Azure region; use virtual network rules where needed. After the change, test that approved connections succeed and unwanted connections are blocked, and review data access permissions.

Examples

These examples compare default allow and default deny settings. They also change the account name from clh0003 to clh0002; when updating an existing account, keep the intended target account consistent. Supply a real resource group, an available account name and authentication settings.

Before

yaml
- name: configure firewall and more virtual networks
  azure_rm_storageaccount:
    resource_group: myResourceGroup
    name: clh0003
    type: Standard_RAGRS
    network_acls:
      bypass: AzureServices,Metrics
      default_action: Allow

After

yaml
- name: configure firewall and virtual networks
  azure_rm_storageaccount:
    resource_group: myResourceGroup
    name: clh0002
    type: Standard_RAGRS
    network_acls:
      bypass: AzureServices,Metrics
      default_action: Deny
      ip_rules:
        - value: 1.2.3.4
          action: Allow

Before: default_action: Allow permits connections from all networks when the public endpoint is enabled. Data access remains subject to separate permissions.

After: The default changes to Deny, with an allow rule for one IP address. Replace the example address 1.2.3.4 with the actual public address of an approved client. Because bypass: AzureServices,Metrics remains, the permitted access also includes those exceptions. Retain only the exceptions you need and test connectivity.

References