説明
テナント間のオブジェクトレプリケーションを許可すると、別のMicrosoft EntraテナントにあるStorageアカウントとレプリケーションポリシーを構成できます。このオプションだけで複製が始まったり、匿名アクセスが許可されたりするわけではありません。
想定される影響
未承認のポリシーが構成されると、組織の管理範囲外にデータがコピーされるおそれがあります。
対処方法
不要な場合は既存のテナント間ポリシーを削除してから、cross_tenant_replication_enabled = falseを設定してください。必要な複製は、宛先とデータの範囲を承認したうえで管理してください。
例
以下はBlob Storageをサポートするアカウントで、テナント間のオブジェクトレプリケーションの許可を変更する例です。
変更前
hcl
resource "azurerm_storage_account" "example" {
name = "examplestorage"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
cross_tenant_replication_enabled = true
}
変更後
hcl
resource "azurerm_storage_account" "example" {
name = "safestorage"
resource_group_name = "testRG"
location = "northeurope"
account_tier = "Standard"
account_replication_type = "LRS"
account_kind = "StorageV2"
cross_tenant_replication_enabled = false
}