Azure Storage account does not require HTTPS

Require HTTPS for Azure Storage REST requests.

Description

Disabling https_only on an Azure Storage account permits HTTP REST requests. Omitting this setting alone does not establish that an existing account permits HTTP.

Potential impact

Storage data and request credentials sent over HTTP can be exposed or modified on the network.

Remediation

Set https_only to true and update application and script URLs to HTTPS. Check existing client compatibility before the change.

Examples

The examples compare only the HTTPS requirement. This setting does not grant access to storage data.

Before

yaml
- name: Storage Account 생성
  azure.azcollection.azure_rm_storageaccount:
    resource_group: myResourceGroup
    name: clh0002
    type: Standard_RAGRS
    https_only: false

After

yaml
- name: Storage Account 생성
  azure.azcollection.azure_rm_storageaccount:
    resource_group: myResourceGroup
    name: clh0002
    type: Standard_RAGRS
    https_only: true

References