Securing Azure Storage with Shared Access Signatures
Pluralsight Hands-On Lab — Storage
At a Glance
| Platform | Pluralsight |
| Category | Azure Storage Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Windows VM via Remote Desktop & Azure Bastion, Azure Storage Explorer, Azure Cloud Shell |
| Completed | 2026 |
Overview
Shared Access Signatures (SAS) provide scoped, time-bound access to Azure Storage without exposing account keys or granting broad RBAC roles. These three Pluralsight labs cover SAS from multiple angles: the full storage account security lifecycle including access keys, SAS tokens, stored access policies, and key rotation; generating a user delegation SAS via Azure CLI backed by an Entra ID identity; and validating least-privilege read-only SAS access using Azure Storage Explorer. Together they demonstrate the complete spectrum of Azure Storage access control patterns.
Lab 1 — Configuration and Security of Azure Storage Accounts
- Created a storage account with LRS redundancy, connected via Azure Storage Explorer using Azure AD, created a blob container named "images", and uploaded image files
- Connected using an account-level access key, uploaded and downloaded files, then rotated key1 to confirm the key-based connection was immediately revoked
- Generated three progressively scoped SAS tokens: Read/List only (access denied at container level), Read/List with Container and Object resource types (list worked, upload blocked), and a third adding Write/Add/Create (upload succeeded)
- Rotated the access key again to revoke all three SAS connections simultaneously — demonstrating key rotation as a bulk revocation mechanism
- Created a Stored Access Policy (Test-SAP) on the images container, generated a container-level SAS linked to the policy, confirmed upload and delete worked, then deleted the policy to immediately revoke the SAS without key rotation
Lab 2 — Secure Storage Access with Shared Access Signatures
- Created a private blob container (contractor-files) and uploaded two sample CSV datasets
- Generated a SAS token with Read and List permissions only and an 8-hour expiry window
- Connected to the lab VM via Azure Bastion, opened Azure Storage Explorer, and attached to the container using the SAS URL
- Verified read and list access by previewing and downloading a CSV file
- Confirmed write and delete were blocked — both a delete attempt and an upload attempt returned insufficient credentials errors, validating least-privilege SAS scoping
Lab 3 — Limit Access Using SAS URI
- Created a blob container (container1) and uploaded two sample text files
- Enabled storage account key access, then generated a SAS token scoped to Blob service with Service, Container, and Object resource types and Read and List permissions only over HTTPS
- Connected via Azure Storage Explorer on the lab VM using the Blob service SAS URL, confirmed both files were visible in the container
- Attempted to delete a file and confirmed the action failed in the Activities pane — validating that Read and List-only permissions correctly blocked destructive operations
← Back to Pluralsight Labs