Description
The AzureServices exception permits network access for specific operations by Microsoft’s designated trusted services. It does not allow every Azure service or replace the authentication and permissions required to access data.
Potential impact
Integrations that rely on this exception can fail when it is absent. Enabling it unnecessarily broadens network access.
Remediation
Check whether the integration requires the exception and include AzureServices in network_acls.bypass only when needed. Consider narrower resource instance rules where supported, and restrict data permissions separately.
Examples
The examples add the service exception while retaining default denial. AzureServices does not select a single service; omit it when no integration needs it.
Before
- name: Storage 방화벽 설정
azure_rm_storageaccount:
resource_group: myResourceGroup
name: clh0002
type: Standard_RAGRS
network_acls:
bypass: Metrics
default_action: Deny
After
- name: Storage 방화벽 설정
azure_rm_storageaccount:
resource_group: myResourceGroup
name: clh0002
type: Standard_RAGRS
network_acls:
bypass: AzureServices,Metrics
default_action: Deny