More Info:

Restricting default network access helps to provide a new layer of security, since storage accounts accept connections from clients on any network. To limit access to selected networks, the default action must be changed.

Risk Level

Medium

Address

Security

Compliance Standards

GDPR, ISO27001, HITRUST, SOC2, NISTCSF, PCIDSS, FedRAMP

Triage and Remediation

Remediation

To remediate the issue of storage accounts allowing public traffic in Azure, you can follow the below steps:

  1. Open the Azure Portal and navigate to the storage account that is allowing public traffic.
  2. Click on “Firewalls and virtual networks” under the “Settings” section in the left-hand menu.
  3. In the “Firewalls and virtual networks” tab, select “Selected networks” under the “Allow access from” section.
  4. Add the IP addresses or ranges that need access to the storage account.
  5. Under the “Network connectivity” section, select “Private endpoint” to restrict access to the storage account to only those clients that have a private endpoint in the same virtual network.
  6. Save the changes.

By following the above steps, you can remediate the issue of storage accounts allowing public traffic in Azure.

Additional Reading: