9.3.3.1 Ensure that 'Default to Microsoft Entra authorization in the Azure portal' is Set to 'Enabled'

Information

When this property is enabled, the Azure portal authorizes requests to blobs, files, queues, and tables with Microsoft Entra ID by default.

Microsoft Entra ID provides superior security and ease of use over Shared Key.

Solution

Remediate from Azure Portal

- Go to Storage accounts.
- Click the name of a storage account.
- Under Settings, click Configuration.
- Under Default to Microsoft Entra authorization in the Azure portal, click the radio button next to Enabled.
- Click Save.
- Repeat steps 1-5 for each storage account requiring remediation.

Remediate from Azure CLI

For each storage account requiring remediation, run the following command to enable defaultToOAuthAuthentication :

az storage account update --resource-group <resource-group> --name <storage-account> --set defaultToOAuthAuthentication=true

See Also

https://workbench.cisecurity.org/benchmarks/24282

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: microsoft_azure

Control ID: 45e0d496cd26f1e42fd70115abd90a79e8954120cfe05b5d2d4a323346d0b7fc