Loading...

Azure Storage updating some default security settings on new accounts - Aug 2023

Azure Storage updating some default security settings on new accounts - Aug 2023

Azure Storage to disable anonymous access and cross-tenant replication on new storage accounts by default  

  

Beginning August 2023, Azure storage will begin phased roll out of changes that disables anonymous access and cross tenant replication for all new storage accounts by default, to align with best practices for security and reduce the risk of data exfiltration. Existing storage accounts will not be impacted by this change. This change will be made to all Azure clouds. 

 

Azure storage gives the ability to configure anonymous access to storage accounts or containers. Anonymous access to containers is already disabled by default to ensure customer data is not vulnerable. With this rollout, anonymous access to storage accounts will also be disabled by default. 

Disabling cross-tenant replication by default will also reduce possibility of data exfiltration due to unintentional or malicious replication of data when the right permissions are given to a user. 

 

While existing storage accounts are not impacted by this change, we highly recommend you follow best practices for security and disable anonymous access and cross tenant replication settings if these capabilities are not required for your scenarios.  

 

Once this rollout is complete,  

  • The new defaults for both these configurations will be applied to all new storage accounts regardless of how they are created, through existing versions of the storage REST API, PowerShell, CLI, SDKs, portal, Azure storage explorer, Terraform.  
  • Applications that require anonymous access to containers/blobs must explicitly configure the storage accounts to be anonymous.  

 

Learn more about how to prepare for anonymous access change and cross-tenant replication change. You can enable these settings for new accounts during or after creation.  

 

To opt-out from disabling anonymous access for your subscription, please register for "EnableAnonymousAccessForNewStorageAccounts" from Azure portal or Powershell or REST API. Please note that opt out will take effect for new accounts starting August 2023.   

 

Help and support 

If you have questions, get answers from community experts in Microsoft Q&A. If you have a support plan and you need technical help, create a support request: 

  • For Issue type, select Technical. 
  • For Subscription, select your subscription. 
  • For Service, select My services. 
  • For Service type, select Blob Storage. 
  • For Resource, select the Azure resource you are creating a support request for. 
  • For Summary, type a description of your issue. 
  • For Problem type, select Authentication and Authorization for anonymous access or Data Migration for cross-tenant replication. 
  • For Problem subtype, select Issues using Anonymous Access for anonymous access or Issues with object replication for cross-tenant replication. 

 

Published on:

Learn more
Azure Storage Blog articles
Azure Storage Blog articles

Azure Storage Blog articles

Share post:

Related posts

Announced at Build 2025: Foundry connection for Azure Cosmos DB, Global Secondary Index, full-text search, and more

The countdown to innovation has begun: Day 1 of Microsoft Build 2025 bought several new announcements, demos, and live coding sessions to in-p...

3 hours ago

Azure MCP Server – May 2025 Release

This post discusses the updates to the Azure MCP (Model Context Protocol) Server for Microsoft //build 2025. The post Azure MCP Server –...

7 hours ago

Accelerating MongoDB Development on Azure: What’s New at Microsoft Build 2025

Microsoft Build 2025 is underway in Seattle, bringing developers together to shape the future of cloud-native app development. If you build Mo...

1 day ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy