Description
A container setting of publicAccess: Blob permits anonymous reads of blobs. Container also permits listing blobs. Neither setting grants write access. Anonymous access requires the storage account to allow it as well, and the account’s network restrictions still apply.
Require authorized requests for logs, backups and business documents that are not intended for public distribution. An account-level prohibition on anonymous access overrides the container setting.
Potential impact
- Anonymous reads can disclose sensitive file contents.
- Blob listings can reveal file names and storage structure.
Remediation
- Set the container’s
publicAccesstoNoneand, where anonymous access is unnecessary, set the account’sallowBlobPublicAccess: false. Check the effect on existing public clients first. - Review data permissions and the scope and expiry of SAS tokens separately. Blocking anonymous access does not revoke existing credentials or SAS permissions.
- Separate intentionally public data from sensitive data and verify that requests without authorization are rejected.
Examples
Supply an existing storage account name and a valid container name. The Blob service name is default. The first example requires an account that already allows anonymous access; do not disable account protection merely to run it.
Before
param storageAccountName string
param containerName string
resource blob_container_example 'Microsoft.Storage/storageAccounts/blobServices/containers@2021-02-01' = {
name: '${storageAccountName}/default/${containerName}'
properties: {
denyEncryptionScopeOverride: true
publicAccess: 'Container'
metadata: {}
}
}
Container permits anonymous reads and blob listings within the account and network restrictions.
After
param storageAccountName string
param containerName string
resource blob_container_example 'Microsoft.Storage/storageAccounts/blobServices/containers@2021-02-01' = {
name: '${storageAccountName}/default/${containerName}'
properties: {
denyEncryptionScopeOverride: true
publicAccess: 'None'
metadata: {}
}
}
None blocks anonymous access to this container. Manage data permissions for authorized requests separately.