Description
When a Storage Account’s public endpoint is enabled, networkAcls.defaultAction set to Allow leaves source networks unrestricted by the firewall. Authentication, permissions and anonymous Blob access are separate, so this setting alone does not make data anonymously public. Restricting access to required networks reduces unnecessary connection paths.
Potential impact
- Networks that do not need access can attempt connections to storage.
- Leaked credentials or other access-control errors may be exploited from a broad network scope.
Remediation
- If using the public endpoint, set networkAcls.defaultAction to Deny and review the required IP rules, virtual network rules and trusted-service exceptions.
- For private-only access, prepare Private Endpoints, DNS and connectivity before disabling public network access. Test required client access and the intended denials.
Examples
These excerpts compare the default firewall action for the same account. Use an actual unique account name. Prepare required allow rules or private connectivity separately for the after configuration.
Before
resource storageAccount 'Microsoft.Storage/storageAccounts@2019-06-01' = {
name: 'examplestorageacct'
location: resourceGroup().location
kind: 'StorageV2'
sku: {
name: 'Standard_LRS'
}
properties: {
networkAcls: {
defaultAction: 'Allow'
}
}
}
The default Allow action does not restrict source networks. Separate permissions still govern data access.
After
resource storageAccount 'Microsoft.Storage/storageAccounts@2021-02-01' = {
name: 'examplestorageacct'
location: resourceGroup().location
kind: 'StorageV2'
sku: {
name: 'Standard_LRS'
}
properties: {
networkAcls: {
defaultAction: 'Deny'
}
}
}
The default action is Deny. This alone neither creates a Private Endpoint nor removes every exception.