Description
An Azure Table stored access policy can grant SAS permissions to query (r), add (a), update (u), and delete (d) entities. Granting all of them allows broad entity access and modification.
Potential impact
Misuse of excessive SAS permissions can expose, add, modify, or delete table entities.
Remediation
Grant only required permissions and use r for query-only access. Also restrict the SAS entity range and validity period.
Examples
The examples narrow the valid Table permissions raud to r. Supply the actual account ID and an appropriate policy validity period.
Before
hcl
resource "azurerm_storage_table" "example" {
name = "mytablename"
storage_account_id = var.storage_account_id
acl {
id = "someid-1XXXXXXXXX"
access_policy {
expiry = var.policy_expiry_utc
permissions = "raud"
start = var.policy_start_utc
}
}
}
After
hcl
resource "azurerm_storage_table" "example" {
name = "mytablename"
storage_account_id = var.storage_account_id
acl {
id = "someid-1XXXXXXXXX"
access_policy {
expiry = var.policy_expiry_utc
permissions = "r"
start = var.policy_start_utc
}
}
}