Review trusted-service exceptions for Azure Storage

Use Azure Storage network exceptions only for required service integrations.

Description

The AzureServices exception permits network access for specific operations by Microsoft’s designated trusted services. It does not allow every Azure service or replace the authentication and permissions required to access data.

Potential impact

Integrations that rely on this exception can fail when it is absent. Enabling it unnecessarily broadens network access.

Remediation

Check whether the integration requires the exception and include AzureServices in network_acls.bypass only when needed. Consider narrower resource instance rules where supported, and restrict data permissions separately.

Examples

The examples add the service exception while retaining default denial. AzureServices does not select a single service; omit it when no integration needs it.

Before

yaml
- name: Storage 방화벽 설정
  azure_rm_storageaccount:
    resource_group: myResourceGroup
    name: clh0002
    type: Standard_RAGRS
    network_acls:
      bypass: Metrics
      default_action: Deny

After

yaml
- name: Storage 방화벽 설정
  azure_rm_storageaccount:
    resource_group: myResourceGroup
    name: clh0002
    type: Standard_RAGRS
    network_acls:
      bypass: AzureServices,Metrics
      default_action: Deny

References