Review secure transfer for Azure Storage

Require encrypted connections for Storage requests.

Description

Azure Storage can accept HTTP requests when secure transfer is not required. Clients using HTTP can expose data and credentials in transit.

Potential impact

An observer able to intercept unencrypted requests may read data or SAS tokens.

Remediation

Set https_traffic_only_enabled = true and configure clients to use HTTPS. For file shares, also verify encrypted SMB connections.

Examples

These excerpts use the current AzureRM secure-transfer option.

Before

hcl
resource "azurerm_storage_account" "example" {
  name                      = "example1"
  resource_group_name       = data.azurerm_resource_group.example.name
  location                  = data.azurerm_resource_group.example.location
  account_tier              = "Standard"
  account_replication_type  = "GRS"
  https_traffic_only_enabled = false
}

After

hcl
resource "azurerm_storage_account" "example" {
  name                      = "example"
  resource_group_name       = data.azurerm_resource_group.example.name
  location                  = data.azurerm_resource_group.example.location
  account_tier              = "Standard"
  account_replication_type  = "GRS"
  https_traffic_only_enabled = true
}

References