Review trusted-service exceptions for Azure Storage

Allow Storage firewall exceptions only for required Azure services.

Description

The AzureServices firewall exception permits supported operations by designated trusted services. Required data permissions remain separate; it does not indiscriminately allow every Azure service.

Potential impact

A missing required exception can disrupt integrations such as backups or diagnostic-log delivery. An unnecessary exception broadens network access.

Remediation

Add AzureServices to bypass and grant the required permissions only when an integration needs it. Keep the exception disabled where it is unnecessary.

Examples

The examples add the trusted-service exception while retaining the default-deny policy.

Before

hcl
resource "azurerm_storage_account" "example" {
  name                = "storageaccountname"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  account_tier        = "Standard"
  account_replication_type = "LRS"

  network_rules {
    default_action             = "Deny"
    bypass                     = ["None"]
    ip_rules                   = ["100.0.0.1"]
    virtual_network_subnet_ids = [azurerm_subnet.example.id]
  }
}

After

hcl
resource "azurerm_storage_account" "example" {
  name                = "storageaccountname"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  account_tier        = "Standard"
  account_replication_type = "LRS"

  network_rules {
    default_action             = "Deny"
    bypass                     = ["AzureServices"]
    ip_rules                   = ["100.0.0.1"]
    virtual_network_subnet_ids = [azurerm_subnet.example.id]
  }
}

References