Azure Storage allows Shared Key access

Reduce account-key use and grant access to individual users and applications.

Description

Shared Key authorizes Storage requests with an account key. Its broad data permissions make access harder to separate and attribute to individual users or applications.

Potential impact

A leaked key can be used for excessive data access or modification.

Remediation

Check clients and SAS usage, then configure supported Microsoft Entra authentication and required roles. Set shared_access_key_enabled = false after verifying compatibility.

Examples

The examples disable Shared Key access. First confirm that Azure Files and operational tools can use alternative authentication.

Before

hcl
resource "azurerm_storage_account" "example" {
  name                     = "examplestorage"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  shared_access_key_enabled = true
}

After

hcl
resource "azurerm_storage_account" "example" {
  name                     = "safestorage"
  resource_group_name      = "testRG"
  location                 = "northeurope"
  account_tier             = "Premium"
  account_replication_type = "LRS"
  account_kind             = "FileStorage"

  shared_access_key_enabled = false
}

References