Description
Allowing cross-tenant object replication permits replication policies with Storage accounts in another Microsoft Entra tenant. The option alone does not start replication or allow anonymous access.
Potential impact
An unapproved replication policy can copy data beyond the organization’s administrative boundary.
Remediation
If it is unnecessary, remove existing cross-tenant replication policies before setting cross_tenant_replication_enabled = false. Approve the destinations and data scope of required replication.
Examples
The examples change whether cross-tenant object replication is allowed on accounts that support Blob Storage.
Before
hcl
resource "azurerm_storage_account" "example" {
name = "examplestorage"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
cross_tenant_replication_enabled = true
}
After
hcl
resource "azurerm_storage_account" "example" {
name = "safestorage"
resource_group_name = "testRG"
location = "northeurope"
account_tier = "Standard"
account_replication_type = "LRS"
account_kind = "StorageV2"
cross_tenant_replication_enabled = false
}