User Delegation SAS — Azure Storage Account

Avanish
3 min readJan 18, 2021

Wikis work best in environments where you’re comfortable delegating control to the users of the system. ~ Howard G. Cunningham

SAS tokens provide limited access to resources in a storage account. We can specify resources clients can access, permissions they can have, and the duration of the access. It also restricts access to specific IP addresses.

Types of SAS tokens —

User Delegation SAS — It is signed with Azure AD Credentials of user/service principal instead of Azure storage keys. Necessary roles…

--

--