Information on Azure Disk Network - Network Access, Public access from all networks

Clive Crocker 66 Reputation points
2024-01-29T13:28:39.5+00:00

Does anyone have useful links which properly explains the setting for Azure Disks (managed) "Network Access - Public access from all networks"? We have Trusted launch VMs and disks, so need to use Enhanced backup. Enhanced backup requires (currently) Public access from all networks. This doesnt sound super-secure... although I think this applies only to unattached disks, and I've read it only applies to public IPs attached to storage accounts, and my managed disks aren't in a storage account. But it's all a bit ambiguous and I'm not clear at all. I am seeking to guard against any possible exfiltration of data but don't feel confident I understand the whole story. Ideally of course I don't want disks accessaible in any way. For example, assuming it is possible, how would disks be accessibe (via Sas token)? I am highly unclear the URL etc. Any guidance / pointers / correction of my misunderstandings would be gratefully received. Thanks

Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
572 questions
0 comments No comments
{count} votes

Accepted answer
  1. TP 76,681 Reputation points
    2024-01-29T14:17:41.3+00:00

    Hi Clive,

    Under your current configuration, in order for a managed disk to be accessible for download it must be a) unattached or the associated VM must be Deallocated AND b) a SAS must be generated. In order to generate the SAS, the user must have necessary permission to the disk.

    To better familiarize yourself, you can perform some quick tests. Create a new resource group, and in that group create a small (B1S) Ubuntu VM with Standard HDD 30GB, no public IP, etc. After creation, immediately Stop it using portal so that it will be Deallocated and not accruing compute charges.

    With this test VM, navigate to its managed disk, click Disk Export blade, click Generate URL button. Once the URL has been generated, if you want you can download the VHD (this will accrue bandwidth charges) or just click Cancel export button.

    Additional tests you could do is give another test user account access to the VM using role assignments, sign in as that user using a different browser profile, and then see if the user is able to generate URL and download the disk.

    Once you are finished testing, please delete the resource group so that you don't accrue any more charges over time.

    Please click Accept Answer and upvote if the above was helpful.

    Thanks.

    -TP

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful