Description
The AzureServices firewall exception permits supported operations by designated trusted services. Required data permissions remain separate; it does not indiscriminately allow every Azure service.
Potential impact
A missing required exception can disrupt integrations such as backups or diagnostic-log delivery. An unnecessary exception broadens network access.
Remediation
Add AzureServices to bypass and grant the required permissions only when an integration needs it. Keep the exception disabled where it is unnecessary.
Examples
The examples add the trusted-service exception while retaining the default-deny policy.
Before
hcl
resource "azurerm_storage_account" "example" {
name = "storageaccountname"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "LRS"
network_rules {
default_action = "Deny"
bypass = ["None"]
ip_rules = ["100.0.0.1"]
virtual_network_subnet_ids = [azurerm_subnet.example.id]
}
}
After
hcl
resource "azurerm_storage_account" "example" {
name = "storageaccountname"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "LRS"
network_rules {
default_action = "Deny"
bypass = ["AzureServices"]
ip_rules = ["100.0.0.1"]
virtual_network_subnet_ids = [azurerm_subnet.example.id]
}
}