Azure Blob container permits public access

Restrict anonymous reads of Azure Blob containers to prevent unintended disclosure of file contents and listings.

Description

A container setting of publicAccess: Blob permits anonymous reads of blobs. Container also permits listing blobs. Neither setting grants write access. Anonymous access requires the storage account to allow it as well, and the account’s network restrictions still apply.

Require authorized requests for logs, backups and business documents that are not intended for public distribution. An account-level prohibition on anonymous access overrides the container setting.

Potential impact

  • Anonymous reads can disclose sensitive file contents.
  • Blob listings can reveal file names and storage structure.

Remediation

  • Set the container’s publicAccess to None and, where anonymous access is unnecessary, set the account’s allowBlobPublicAccess: false. Check the effect on existing public clients first.
  • Review data permissions and the scope and expiry of SAS tokens separately. Blocking anonymous access does not revoke existing credentials or SAS permissions.
  • Separate intentionally public data from sensitive data and verify that requests without authorization are rejected.

Examples

Supply an existing storage account name and a valid container name. The Blob service name is default. The first example requires an account that already allows anonymous access; do not disable account protection merely to run it.

Before

bicep
param storageAccountName string
param containerName string

resource blob_container_example 'Microsoft.Storage/storageAccounts/blobServices/containers@2021-02-01' = {
  name: '${storageAccountName}/default/${containerName}'
  properties: {
    denyEncryptionScopeOverride: true
    publicAccess: 'Container'
    metadata: {}
  }
}

Container permits anonymous reads and blob listings within the account and network restrictions.

After

bicep
param storageAccountName string
param containerName string

resource blob_container_example 'Microsoft.Storage/storageAccounts/blobServices/containers@2021-02-01' = {
  name: '${storageAccountName}/default/${containerName}'
  properties: {
    denyEncryptionScopeOverride: true
    publicAccess: 'None'
    metadata: {}
  }
}

None blocks anonymous access to this container. Manage data permissions for authorized requests separately.

References