Azure Storage Account - Container cambia access level in automatico

ducarpit 0 Punti di reputazione
2026-02-04T14:17:20.6033333+00:00

Buonasera,

su Azure ho uno Storage Account con accesso anonimo abilitato, al suo interno ci sono diversi container con Access Level impostato su "Private" ed uno impostato s "Container".

Ho impostato quest'ultimo a "Blob" ma dopo un pò di tempo torna in automatico a "Container" e dai log non riesco a capire chi lo modifica e perchè. Considerando che sono l'unico amministratore dell'account e quindi non può essere un'azione umana...

Avete qualche idea?

Grazie in anticipo,

Christian

Archiviazione BLOB di Azure
0 commenti Nessun commento

2 risposte

Ordina per: Più utili
  1. ducarpit 0 Punti di reputazione
    2026-02-09T14:02:33.8833333+00:00

    Maybe, i found the "problem"...
    Some months ago, i enabled the backup on this container within the storage account, and i set the georeplica.

    It seems there is a policy that restore the access level when the replica syns run.
    I found it with:

    az storage account or-policy list --account-name <account_name> --resource-group <resource_group> -o json
    
    

    ChatGTP says this is the "guilty".
    I have also another storage account with a separate coninter and the same backup enabled but without georeplicas and i don't notice this behavior.
    Do you think this is could be right?
    Thanks

    La risposta è stata utile?

    0 commenti Nessun commento

  2. Ganesh Patapati 12,170 Punti di reputazione Personale Esterno Microsoft Moderatore
    2026-02-04T18:13:53.0066667+00:00

    Hello Ducarpit

    you can check this over Activity log in the azure portal.

    1. Open Azure Portal
    2. Go to your Storage Account
    3. In the left pane → Monitoring → Activity log
    4. Immagine dell'utente
    • In the above screenshot go for Operation name
    • Click on Update Storage account Create.
    • Immagine dell'utente
    • Next, go to change history where you can view the resource updates.
    • Click on Resource Update to see the change logs and who made the updates.
    • Then check the properties to see who made the changes or see if there is any policy in place.
    • Immagine dell'utente

    NOTE: Confirm that your storage account configuration aligns with your intended access policies, especially considering anonymous access settings.

    To figure out what's causing the changes to the access level, you should review the storage analytic blob logs for any calls made to the Set Container ACL API. This API tracks who made the changes, along with details like user agent and client IP address.

    References:

    Hope the above answer helps! Please let us know do you have any further queries.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    La risposta è stata utile?


Risposta

Le risposte possono essere contrassegnate come "Accettata" dall'autore della domanda e "Consigliata" dai moderatori, in modo da consentire agli utenti di sapere che la risposta ha risolto il problema dell'autore.