last sync: 2025-Aug-01 17:23:26 UTC

Enforce storage account public firewall blocking access

Community Policy definition

Source Repository Community-Policy GitHub
JSON Community-Policy GitHub
Deploy policy ed1e9c2b-f8e2-48e8-8bf6-43247c3c8401 (1.0.0) to Azure
Display name Enforce storage account public firewall blocking access
Id ed1e9c2b-f8e2-48e8-8bf6-43247c3c8401
Version 1.0.0
Details on versioning
Category Storage
Microsoft Learn
Description This policy prevents setting storage public firewall as allow all or have any vnet/ip rules.
Mode Indexed
Type Custom Community
Effect Default
Audit
Allowed
Deny, Audit, Disabled
RBAC role(s) none
Rule aliases IF (3)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Storage/storageAccounts/networkAcls.defaultAction Microsoft.Storage storageAccounts properties.networkAcls.defaultAction True True
Microsoft.Storage/storageAccounts/networkAcls.ipRules Microsoft.Storage storageAccounts properties.networkAcls.ipRules True True
Microsoft.Storage/storageAccounts/networkAcls.virtualNetworkRules Microsoft.Storage storageAccounts properties.networkAcls.virtualNetworkRules True True
Rule resource types IF (1)
Microsoft.Storage/storageAccounts
JSON
EPAC
Deploy policy ed1e9c2b-f8e2-48e8-8bf6-43247c3c8401 (1.0.0) to Azure