Description
Disabling supportsHttpsTrafficOnly can allow storage REST requests over HTTP. If clients actually use HTTP, data and SAS tokens can be exposed in transit. HTTPS, encryption at rest, and access permissions are separate controls.
Potential impact
- Files, request information, or tokens sent in plaintext can be observed or altered along the connection path.
- Old HTTP clients can fail after secure transfer is required if they have not been updated.
Remediation
Set supportsHttpsTrafficOnly to true and update applications, backup tools, and scripts to use HTTPS from the start. Retain TLS certificate validation and test HTTP rejection and HTTPS success. For other protocols, including SMB and NFS, separately review service encryption and compatibility requirements.
Examples
These excerpts compare transfer settings on the same storage account. Supply its actual unique name, location, SKU, account kind, and other required inputs separately.
Before
resource storageaccount1 'Microsoft.Storage/storageAccounts@2021-02-01' = {
name: 'storageaccount1'
properties: {
supportsHttpsTrafficOnly: false
}
}
This disables the HTTPS requirement. It does not mean every client uses plaintext, but this control does not prevent HTTP requests.
After
resource storageaccount1Negative1 'Microsoft.Storage/storageAccounts@2021-02-01' = {
name: 'storageaccount1'
properties: {
supportsHttpsTrafficOnly: true
}
}
This requires HTTPS for storage REST requests. It cannot retroactively encrypt a request that a client already sent in plaintext.