ID Posture
STORAGE SECURITY

One misconfigured storage account is all it takes

Shared key access, public blob access, network exposure, transport security, ID Posture checks the settings that turn a normal storage account into an open one.

WHAT WE CHECK

Seven findings, checked on every scan

Ask your ID Posture contact to enable Storage Security for your tenant.

app.idposture.io/storage-security
Storage account allows anonymous public blob access
High
Storage account allows public access from all networks
High
Storage account does not require secure transfer (HTTPS)
High
Storage account allows shared key (access key) authentication
Medium
Storage account allows an outdated minimum TLS version
Medium
Storage account restricted to specific virtual networks and IP addresses (partial)
Low
Azure portal's default authorization method is not set to Microsoft Entra ID
Low

Why it matters

Anonymous public blob access is an account-level switch that permits any container to be made public, one misconfigured container and its contents are reachable by anyone on the internet, no account or key required. Shared key access means a leaked access key bypasses Entra ID entirely. HTTP without enforced HTTPS means credentials and data can travel in the clear. None of these are exotic misconfigurations, they're settings every storage account has, most left at Azure's own historical defaults. ID Posture checks all seven on every scan, plus a plain inventory of copy scope and access tier.

Part of ID Posture’s broader Azure resource coverage. See the full product overview, or explore AKS Security and AI Agent Identity.

Ask your ID Posture contact to enable Storage Security

It's optional, per tenant, and off by default until you ask for it.

Contact us