Aracılığıyla paylaş


Overview: Remediating anonymous read access for blob data

Azure Depolama, kapsayıcılar ve bloblar için isteğe bağlı anonim okuma erişimini destekler. Varsayılan olarak, verilerinize anonim erişime hiçbir zaman izin verilmez. Anonim erişimi açıkça etkinleştirmediğiniz sürece, bir kapsayıcıya ve bloblarına yönelik tüm istekler yetkilendirilmelidir. Tüm depolama hesaplarınız için anonim erişimi devre dışı bırakmanızı öneririz.

This article provides an overview of how to remediate anonymous access for your storage accounts.

Uyarı

Anonymous access presents a security risk. We recommend that you take the actions described in the following section to remediate anonymous access for all of your storage accounts, unless your scenario specifically requires anonymous access.

Recommendations for remediating anonymous access

You can remediate anonymous access for an account at any time by setting the account's AllowBlobPublicAccess property to False. After you set the AllowBlobPublicAccess property to False, all requests for blob data to that storage account will require authorization, regardless of the anonymous access setting for any individual container.

To learn more about how to remediate anonymous access for Azure Resource Manager accounts, see Remediate anonymous read access to blob data.

Scenarios requiring anonymous access

If your scenario requires that certain containers need to be available for anonymous access, then you should move those containers and their blobs into separate storage accounts that are reserved only for anonymous access. You can then disallow anonymous access for any other storage accounts using the recommendations provided in Recommendations for remediating anonymous access.

For information on how to configure containers for anonymous access, see Configure anonymous read access for containers and blobs.

Sonraki adımlar