Description
Broad network access or anonymous Blob access on an Azure Storage Account can expose data to unintended recipients. Being able to reach the account over a network and being able to read data without authentication are separate conditions.
Allowing Blob public access on the account does not automatically make every container public. Container access levels and network restrictions also apply, while authenticated data access requires the appropriate permissions.
Potential impact
- Data in a publicly configured container may be read by unintended users.
- Broad network access can weaken restrictions on misuse of leaked credentials.
Remediation
Disable unnecessary anonymous Blob access on the account and containers. If the public endpoint is needed, set the default network action to Deny and allow only approved public IP addresses or subnets. For private-only connectivity, configure and test private endpoints and DNS before disabling public network access. Verify data permissions and access for intended clients too.
Examples
These examples retain AzureRM 2.99.0 syntax. allow_blob_public_access is an older attribute name; use the attribute supported by your installed provider version. Replace the sample IP address with an approved actual public address.
Before
resource "azurerm_storage_account" "app_storage" {
name = "storageaccountname"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "LRS"
network_rules {
default_action = "Deny"
ip_rules = ["0.0.0.0/0"]
}
}
0.0.0.0/0 is a broad CIDR that does not narrow the address range. This setting alone does not enable anonymous Blob reads.
After
resource "azurerm_storage_account" "app_storage" {
name = "storageaccountname"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "LRS"
allow_blob_public_access = false
network_rules {
default_action = "Deny"
ip_rules = ["100.0.0.1"]
}
}
This narrows network access to one address and disables anonymous Blob access at the account level. Clients on an allowed network still need data access permissions.