last sync: 2025-Jun-04 17:22:52 UTC

[Deprecated]: Require blob encryption for storage accounts

Azure BuiltIn Policy definition

Source Azure Portal
Display name [Deprecated]: Require blob encryption for storage accounts
Id 7c5a74bf-ae94-4a74-8fcf-644d1e0e6e6f
Version 1.0.0-deprecated
Details on versioning
Versioning Versions supported for Versioning: 1
1.0.0 (1.0.0-deprecated)
Built-in Versioning [Preview]
Category Storage
Microsoft Learn
Description This policy ensures blob encryption for storage accounts is turned on. It only applies to Microsoft.Storage resource types, not other storage providers. This policy is deprecated because storage blob encryption is now enabled by default, and can no longer be disabled.
Cloud environments AzureCloud = true
AzureUSGovernment = unknown
AzureChinaCloud = unknown
Available in AzUSGov Unknown, no evidence if Policy definition is/not available in AzureUSGovernment
Mode Indexed
Type BuiltIn
Preview False
Deprecated True
Effect Fixed
deny
RBAC role(s) none
Rule aliases IF (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Storage/storageAccounts/enableBlobEncryption Microsoft.Storage storageAccounts properties.encryption.services.blob.enabled True False
Rule resource types IF (1)
Compliance Not a Compliance control
Initiatives usage none
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC