Description
Shared Key authorizes Storage requests with an account key. Its broad data permissions make access harder to separate and attribute to individual users or applications.
Potential impact
A leaked key can be used for excessive data access or modification.
Remediation
Check clients and SAS usage, then configure supported Microsoft Entra authentication and required roles. Set shared_access_key_enabled = false after verifying compatibility.
Examples
The examples disable Shared Key access. First confirm that Azure Files and operational tools can use alternative authentication.
Before
hcl
resource "azurerm_storage_account" "example" {
name = "examplestorage"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
shared_access_key_enabled = true
}
After
hcl
resource "azurerm_storage_account" "example" {
name = "safestorage"
resource_group_name = "testRG"
location = "northeurope"
account_tier = "Premium"
account_replication_type = "LRS"
account_kind = "FileStorage"
shared_access_key_enabled = false
}