-
Notifications
You must be signed in to change notification settings - Fork 3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Storage] BREAKING CHANGE: az storage account create
: Server change default value for --allow-blob-public-access
and --allow-cross-tenant-replication
to False
for new accounts
#28091
Merged
calvinhzy
merged 1 commit into
Azure:dev
from
calvinhzy:storage-account-create-service-breaking-change
Dec 26, 2023
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
… and `--allow-cross-tenant-replication` to False for new accounts
calvinhzy
requested review from
jsntcy,
zhoxing-ms and
evelyn-ys
as code owners
December 25, 2023 09:20
️✔️AzureCLI-FullTest
|
Hi @calvinhzy, |
️✔️AzureCLI-BreakingChangeTest
|
Storage |
calvinhzy
changed the title
[Storage] BREAKING CHANGE:
[Storage] BREAKING CHANGE: Dec 25, 2023
az storage account create
: Server change default value for --allow-blob-public-access
and --allow-cross-tenant-replication
to False for new accountsaz storage account create
: Server change default value for --allow-blob-public-access
and --allow-cross-tenant-replication
to False
for new accounts
evelyn-ys
approved these changes
Dec 26, 2023
MaxHorstmann
pushed a commit
to MaxHorstmann/azure-cli
that referenced
this pull request
Jan 19, 2024
… default value for `--allow-blob-public-access` and `--allow-cross-tenant-replication` to `False` for security concerns (Azure#28091)
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Related command
Description
Beginning December 2023, there are server breaking changes to these default security settings when creating a storage account for security concerns.
--allow-blob-public-acces
s will default toFalse
instead ofTrue
now--allow-cross-tenant-replication
will default toFalse
instead ofTrue
now.Please see the blog post about the security risk and server change details:
https://techcommunity.microsoft.com/t5/azure-storage-blog/azure-storage-updating-some-default-security-settings-on-new/ba-p/3819554
Testing Guide
History Notes
[Storage] BREAKING CHANGE:
az storage account create
: Server change default value for--allow-blob-public-access
and--allow-cross-tenant-replication
toFalse
for security concernsThis checklist is used to make sure that common guidelines for a pull request are followed.
The PR title and description has followed the guideline in Submitting Pull Requests.
I adhere to the Command Guidelines.
I adhere to the Error Handling Guidelines.