Azure Storage Account public-access settings need review

Check network reachability and anonymous Blob access separately.

Description

Broad network access or anonymous Blob access on an Azure Storage Account can expose data to unintended recipients. Being able to reach the account over a network and being able to read data without authentication are separate conditions.

Allowing Blob public access on the account does not automatically make every container public. Container access levels and network restrictions also apply, while authenticated data access requires the appropriate permissions.

Potential impact

  • Data in a publicly configured container may be read by unintended users.
  • Broad network access can weaken restrictions on misuse of leaked credentials.

Remediation

Disable unnecessary anonymous Blob access on the account and containers. If the public endpoint is needed, set the default network action to Deny and allow only approved public IP addresses or subnets. For private-only connectivity, configure and test private endpoints and DNS before disabling public network access. Verify data permissions and access for intended clients too.

Examples

These examples retain AzureRM 2.99.0 syntax. allow_blob_public_access is an older attribute name; use the attribute supported by your installed provider version. Replace the sample IP address with an approved actual public address.

Before

hcl
resource "azurerm_storage_account" "app_storage" {
  name                     = "storageaccountname"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "LRS"

  network_rules {
    default_action = "Deny"
    ip_rules       = ["0.0.0.0/0"]
  }
}

0.0.0.0/0 is a broad CIDR that does not narrow the address range. This setting alone does not enable anonymous Blob reads.

After

hcl
resource "azurerm_storage_account" "app_storage" {
  name                     = "storageaccountname"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "LRS"
  allow_blob_public_access = false

  network_rules {
    default_action = "Deny"
    ip_rules       = ["100.0.0.1"]
  }
}

This narrows network access to one address and disables anonymous Blob access at the account level. Clients on an allowed network still need data access permissions.

References