Skip to content

Commit 3621846

Browse files
benbpazure-sdk
authored andcommitted
Set storage account test resources to disable blob public access
1 parent 758b745 commit 3621846

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

eng/common/scripts/Helpers/Resource-Helpers.ps1

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -319,7 +319,14 @@ function SetStorageNetworkAccessRules([string]$ResourceGroupName, [array]$AllowI
319319
if ($storageAccounts) {
320320
$appliedRule = $false
321321
foreach ($account in $storageAccounts) {
322+
$properties = Get-AzStorageAccount -ResourceGroupName $ResourceGroupName -AccountName $account.Name
322323
$rules = Get-AzStorageAccountNetworkRuleSet -ResourceGroupName $ResourceGroupName -AccountName $account.Name
324+
325+
if ($properties.AllowBlobPublicAccess) {
326+
Write-Host "Restricting public blob access in storage account '$($account.Name)'"
327+
Set-AzStorageAccount -ResourceGroupName $ResourceGroupName -StorageAccountName $account.Name -AllowBlobPublicAccess $false
328+
}
329+
323330
if ($rules -and ($Override -or $rules.DefaultAction -eq "Allow")) {
324331
Write-Host "Restricting network rules in storage account '$($account.Name)' to deny access by default"
325332
Retry { Update-AzStorageAccountNetworkRuleSet -ResourceGroupName $ResourceGroupName -Name $account.Name -DefaultAction Deny }

0 commit comments

Comments
 (0)