Description
When enableHttpsTrafficOnly is false, an Azure Storage Account may accept HTTP REST requests. Tools or scripts using HTTP transfer data over an unencrypted connection.
Potential impact
- Data sent to or from storage may be exposed in plaintext.
- An attacker with access to the traffic path may intercept or alter data or credentials.
Remediation
Set enableHttpsTrafficOnly to true. Verify that applications, operational scripts, and external integrations use HTTPS endpoints, and review network rules and the minimum TLS version.
Examples
These excerpts compare the account’s transfer setting. The resource group, location, SKU, and other account settings are omitted.
Before
yaml
resources:
storageAccount:
type: azure-native:storage:StorageAccount
properties:
accountName: sto4445
enableHttpsTrafficOnly: false
After
yaml
resources:
storageAccount:
type: azure-native:storage:StorageAccount
properties:
accountName: sto4445
enableHttpsTrafficOnly: true
Requiring secure transfer rejects HTTP REST requests. Verify HTTPS connectivity for existing clients. Encryption at rest and access permissions are separate controls.