Azure Storage allows cross-tenant object replication

Allow cross-tenant object replication only for approved purposes.

Description

Allowing cross-tenant object replication permits replication policies with Storage accounts in another Microsoft Entra tenant. The option alone does not start replication or allow anonymous access.

Potential impact

An unapproved replication policy can copy data beyond the organization’s administrative boundary.

Remediation

If it is unnecessary, remove existing cross-tenant replication policies before setting cross_tenant_replication_enabled = false. Approve the destinations and data scope of required replication.

Examples

The examples change whether cross-tenant object replication is allowed on accounts that support Blob Storage.

Before

hcl
resource "azurerm_storage_account" "example" {
  name                     = "examplestorage"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  cross_tenant_replication_enabled = true
}

After

hcl
resource "azurerm_storage_account" "example" {
  name                     = "safestorage"
  resource_group_name      = "testRG"
  location                 = "northeurope"
  account_tier             = "Standard"
  account_replication_type = "LRS"
  account_kind             = "StorageV2"

  cross_tenant_replication_enabled = false
}

References