Excessive permissions in an Azure file-share access policy

Grant only the permissions a file-share SAS needs.

Description

An Azure file share’s stored access policy defines permissions for SAS tokens that reference it. rwdl combines file read, write, delete, and listing permissions.

Potential impact

A leaked or misused token can expose, modify, or delete files beyond the intended scope.

Remediation

Keep only permissions required for the task; use r for read-only access. Limit the policy’s validity period to the required interval.

Examples

The examples narrow access to read-only. Supply valid UTC start and expiry inputs, with expiry later than start.

Before

hcl
resource "azurerm_storage_share_file" "example" {
  name             = "my-awesome-content.zip"
  storage_share_id = azurerm_storage_share.example.id
  source           = "some-local-file.zip"
}

resource "azurerm_storage_share" "example" {
  name                 = "sharename"
  storage_account_id   = azurerm_storage_account.example.id
  quota                = 50

  acl {
    id = "MTIzNDU2Nzg5MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTI"

    access_policy {
      permissions = "rwdl"
      start       = var.policy_start_utc
      expiry      = var.policy_expiry_utc
    }
  }
}

After

hcl
resource "azurerm_storage_share_file" "example" {
  name             = "my-awesome-content.zip"
  storage_share_id = azurerm_storage_share.example.id
  source           = "some-local-file.zip"
}

resource "azurerm_storage_share" "example" {
  name                 = "sharename"
  storage_account_id   = azurerm_storage_account.example.id
  quota                = 50

  acl {
    id = "MTIzNDU2Nzg5MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTI"

    access_policy {
      permissions = "r"
      start       = var.policy_start_utc
      expiry      = var.policy_expiry_utc
    }
  }
}

References