AzureSecurity icon indicating copy to clipboard operation
AzureSecurity copied to clipboard

You can use Azure Ad instead of the access key

Open Boaz101 opened this issue 4 years ago • 0 comments

Instead of storing the storage account's access key in Key Vault. You can set the use_azuread_auth flag to true. Then give your service principal access to the storage account container. Then disable access key usable on the storage account. This way terraform has less permissions on the storage account and no one can get into the storage account using the access key.

Boaz101 avatar Jun 28 '21 19:06 Boaz101