Description
An Azure Storage public endpoint open to every network allows clients outside the workload's intended network to attempt data access. In Ansible, network_acls.default_action: Allow leaves that public endpoint unrestricted by the firewall's default policy. Even with Deny, overly broad address ranges or service exceptions can allow more connections than intended.
Azure gives public_network_access precedence over the firewall's default action. When disabling public access, also review existing trusted-service and resource-instance exceptions. Permission to connect through the network boundary is separate from permission to read or write data. An open public endpoint does not by itself grant anonymous access.
Potential impact
- Broad network access can allow leaked credentials or excessive data permissions to be abused from networks that have no business need to connect.
- Protecting sensitive data requires both restricted client connection paths and appropriate data permissions.
Remediation
- If the public endpoint is needed, set
network_acls.default_actiontoDenyand allow only required public IPv4 addresses or virtual networks. Keep resource-instance rules andbypassexceptions limited to their required purposes. - If only private connectivity is needed, configure private endpoints for the storage services in use and their DNS before applying
public_network_access: Disabled. Creating a private endpoint does not block public access by itself. Review any retained service and resource-instance exceptions. - Use the client's actual public source address in IP rules. IP rules do not apply to requests from the same Azure region; use virtual network rules where needed. After the change, test that approved connections succeed and unwanted connections are blocked, and review data access permissions.
Examples
These examples compare default allow and default deny settings. They also change the account name from clh0003 to clh0002; when updating an existing account, keep the intended target account consistent. Supply a real resource group, an available account name and authentication settings.
Before
- name: configure firewall and more virtual networks
azure_rm_storageaccount:
resource_group: myResourceGroup
name: clh0003
type: Standard_RAGRS
network_acls:
bypass: AzureServices,Metrics
default_action: Allow
After
- name: configure firewall and virtual networks
azure_rm_storageaccount:
resource_group: myResourceGroup
name: clh0002
type: Standard_RAGRS
network_acls:
bypass: AzureServices,Metrics
default_action: Deny
ip_rules:
- value: 1.2.3.4
action: Allow
Before: default_action: Allow permits connections from all networks when the public endpoint is enabled. Data access remains subject to separate permissions.
After: The default changes to Deny, with an allow rule for one IP address. Replace the example address 1.2.3.4 with the actual public address of an approved client. Because bypass: AzureServices,Metrics remains, the permitted access also includes those exceptions. Retain only the exceptions you need and test connectivity.
References
- CWE-284
- Ansible azure.azcollection.azure_rm_storageaccount documentation
- Ansible azure.azcollection 3.21.0 storage-account module implementation
- Azure Storage firewall and data access requirements
- Public access precedence, exceptions and IP-rule limitations
- Applying default network restrictions
- Storage private endpoints