Azure Storage does not enforce HTTPS

Require secure transfer for Azure Storage and verify that REST requests use HTTPS.

Description

When enableHttpsTrafficOnly is false, an Azure Storage Account may accept HTTP REST requests. Tools or scripts using HTTP transfer data over an unencrypted connection.

Potential impact

  • Data sent to or from storage may be exposed in plaintext.
  • An attacker with access to the traffic path may intercept or alter data or credentials.

Remediation

Set enableHttpsTrafficOnly to true. Verify that applications, operational scripts, and external integrations use HTTPS endpoints, and review network rules and the minimum TLS version.

Examples

These excerpts compare the account’s transfer setting. The resource group, location, SKU, and other account settings are omitted.

Before

yaml
resources:
  storageAccount:
    type: azure-native:storage:StorageAccount
    properties:
      accountName: sto4445
      enableHttpsTrafficOnly: false

After

yaml
resources:
  storageAccount:
    type: azure-native:storage:StorageAccount
    properties:
      accountName: sto4445
      enableHttpsTrafficOnly: true

Requiring secure transfer rejects HTTP REST requests. Verify HTTPS connectivity for existing clients. Encryption at rest and access permissions are separate controls.

References