Skip to content

[RULE] Disable local auth for storage accounts #3115

@BernieWhite

Description

@BernieWhite

Existing rule

No response

Suggested rule

Storage accounts allow disabling local accounts which disables both access keys and SAS tokens.

This is configured by setting the allowSharedKeyAccess property to false.

Access keys allow depersonalized access to a Storage Account using a shared secret.

Pillar

Security

Additional context

Create a new YAML based rule named Azure.Storage.LocalAuth.

Similar rules:

  • Azure.Redis.LocalAuth
  • Azure.AI.DisableLocalAuth
  • Azure.Cosmos.DisableLocalAuth

This should have the labels: Azure.WAF/maturity: L1 and Azure.MCSB.v1/control: IM-1.

Use rule ref AZR-000497.

References:

Metadata

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions