Defender for Storage: Missing On-Upload Verdicts for Benign Small BlockBlob Uploads — Investigation Needed

ZimElectric-5201 0 Reputation points
2026-10-07T21:48:12.6866667+00:00

Problem description

I am experiencing an issue where small benign BlockBlob uploads to Azure Blob Storage are not producing the expected on-upload malware scan verdicts in Defender for Storage. Specifically, the uploaded files do not show the clean verdict as anticipated, and the 'Malware scanning scan result' tags are absent for these files, despite the configuration being set correctly.

Environment

Azure Blob Storage in a General Purpose v2 storage account, Region: East US, with Microsoft Defender for Storage enabled, on-upload malware scanning active with a 10 GB monthly cap, and scan results configured to blob index tags.

What I've already tried

I verified the Defender for Storage and malware scanning configurations, including the on-upload scan cap, event grid setup, and permissions. I also checked the existence of the event system topic, the scanner identity roles, and the ability to read blob tags. Additionally, I attempted on-demand scans via API, which resulted in errors indicating issues with request formatting and scan result retrieval. I have also corrected permission gaps and confirmed the scanner's identity has the necessary roles.

Current status

The issue persists where small benign uploads do not show the expected scan verdicts, and the scan results are not published as blob index tags. I am seeking guidance on verifying the end-to-end scan and result publication path, understanding why verdicts are absent, and how to obtain verifiable results for existing retained files without overwriting originals.

Azure Blob Storage
Azure Blob Storage

An Azure service that stores unstructured data in the cloud as blobs.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Allan Solomon Mejia 10,305 Reputation points
    2026-10-08T03:03:35.33+00:00

    Hell @ZimElectric-5201

    The absence of a verdict isn’t expected merely because the uploaded blob is small. Microsoft doesn’t document a minimum blob size for malware scanning.

    A few points are important here:

    • On-upload scanning starts only after an operation generates a BlobCreated or BlobRenamed event. For block blobs, individual PutBlock operations don’t trigger scanning; the scan starts after the blocks are committed with PutBlockList.
    • Blob-index tags are the default result method, but they can be disabled. Event Grid and Log Analytics delivery must be configured separately. The expected tag values include No threats found, Malicious, Error, and Not scanned.
    • A blob can have no result if the storage account exceeds documented scan throughput or blob-size limits. Failed and unsupported scans should normally return an error or Not scanned reason when results are successfully published.
    • For Event Grid, confirm that the Defender for Storage settings reference the intended custom topic and that the subscription is receiving Defender malware-scan events. A normal storage BlobCreated subscription isn’t the same as the Defender scan-result configuration.

    For retained blobs, use Defender for Storage on-demand malware scanning. It can scan existing data and can target an individual blob, container, path prefix, or the storage account. It doesn’t require re-uploading or replacing the original blob. Check the scan operation’s status and summary through the documented scan-status API instead of treating the initial request response as the verdict.

    Capture the exact upload operation, blob URL, UTC upload time, storage-account resource ID, current Defender settings, and any on-demand API response body. If the upload was finalized correctly, blob-index result storage is enabled, limits weren’t exceeded, and neither tags nor configured Event Grid/Log Analytics results appear, this requires an Azure support case to inspect the Defender scanning backend.

    There's no verified official documentation identifying a known issue specifically affecting benign small block blobs in East US.

    References:

    On-upload malware scanning

    Introduction to malware scanning

    Understand malware-scanning results

    Configure malware-scan result handling

    On-demand malware scanning


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.