Securing Azure Storage with Shared Access Signatures

Pluralsight Hands-On Lab — Azure Storage Security

Securing Azure Storage with Shared Access Signatures

Pluralsight Hands-On Lab — Storage


At a Glance

PlatformPluralsight
CategoryAzure Storage Security
Lab TypeGuided + Challenge Mode
EnvironmentAzure Portal, Windows VM via Remote Desktop & Azure Bastion, Azure Storage Explorer, Azure Cloud Shell
Completed2026

Overview

Shared Access Signatures (SAS) provide scoped, time-bound access to Azure Storage without exposing account keys or granting broad RBAC roles. These three Pluralsight labs cover SAS from multiple angles: the full storage account security lifecycle including access keys, SAS tokens, stored access policies, and key rotation; generating a user delegation SAS via Azure CLI backed by an Entra ID identity; and validating least-privilege read-only SAS access using Azure Storage Explorer. Together they demonstrate the complete spectrum of Azure Storage access control patterns.


Lab 1 — Configuration and Security of Azure Storage Accounts


Lab 2 — Secure Storage Access with Shared Access Signatures


Lab 3 — Limit Access Using SAS URI


← Back to Pluralsight Labs