Excessive permissions in an Azure Table access policy

Limit Table SAS permissions to required entity operations.

Description

An Azure Table stored access policy can grant SAS permissions to query (r), add (a), update (u), and delete (d) entities. Granting all of them allows broad entity access and modification.

Potential impact

Misuse of excessive SAS permissions can expose, add, modify, or delete table entities.

Remediation

Grant only required permissions and use r for query-only access. Also restrict the SAS entity range and validity period.

Examples

The examples narrow the valid Table permissions raud to r. Supply the actual account ID and an appropriate policy validity period.

Before

hcl
resource "azurerm_storage_table" "example" {
  name                 = "mytablename"
  storage_account_id   = var.storage_account_id

  acl {
    id = "someid-1XXXXXXXXX"

    access_policy {
      expiry      = var.policy_expiry_utc
      permissions = "raud"
      start       = var.policy_start_utc
    }
  }
}

After

hcl
resource "azurerm_storage_table" "example" {
  name                 = "mytablename"
  storage_account_id   = var.storage_account_id

  acl {
    id = "someid-1XXXXXXXXX"

    access_policy {
      expiry      = var.policy_expiry_utc
      permissions = "r"
      start       = var.policy_start_utc
    }
  }
}

References