Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 4 Current »

Severity : High

Description: This control ensures that Trusted Microsoft Services' is enabled for Storage Account access. To help some MS services to interact with storage account, it is require to bypass the network rules. These services will use strong authentication to access the storage account. If the Allow trusted Microsoft services exception is enabled, services like Azure Backup, Azure Site Recovery, Azure DevTest Labs, Azure Event Grid, Azure Event Hubs, Azure Networking, Azure Monitor and Azure SQL Data Warehouse are granted access to the storage account.

Remediation Steps:

Perform following to update parameters:

  1. Login to Azure Portal using https://portal.azure.com.

  2. Go to Storage Accounts.

  3. For each storage account, click on the Networking  under Settings.

  4. Go to Firewalls and virtual networks.

  5. Ensure that you have elected to allow access from Selected networks.

  6. Enable check box for Allow trusted Microsoft services to access this storage account.

  7. Click Save.

Important:

Reference:

  • No labels