Skip to main content
compliance · azure

Azure storage accounts that accept REST requests over plain HTTP

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags a storage account whose `enableHttpsTrafficOnly` (secure transfer required) setting is false, which lets REST calls to blobs, queues, tables and files arrive over plain HTTP. Azure enables secure transfer by default on new accounts, so a finding means it was turned off. Severity is high and no saving is claimed.

Signal and threshold

How ZopNight evaluates Azure storage accounts that accept REST requests over plain HTTP.
Field Value
Rule IDsRC-1322
Categorycompliance
Severityhigh
Metricnone — pure configuration read
ThresholdenableHttpsTrafficOnly = false
SourceZopNight
Permissions usedMicrosoft.Storage/storageAccounts/read

Secure transfer is on by default for a reason

When secure transfer is required, every call to an Azure Storage REST API operation must use HTTPS and any HTTP request is rejected. Microsoft enables the property by default when an account is created.

Turn it off and requests carrying authorization headers, SAS tokens in URLs and the data itself can travel unencrypted. Anyone on the network path can read or alter them.

Listing accounts that allow HTTP

Terminal window
az storage account list \
--query "[?enableHttpsTrafficOnly==\`false\`].{name:name, rg:resourceGroup}" -o table

Each row is an account where the secure transfer requirement is off.

The property behind the finding

ZopNight reads the account’s secure-transfer setting from Azure and fires when it is explicitly false. It is a configuration read with no metric or window, repeated every scan, and cleared as soon as Azure reports the setting on.

Accounts that are not flagged

If the setting was not returned for an account, ZopNight treats it as unknown and raises no finding. Tags on the account are not consulted. This check looks only at REST traffic; Azure Files now has separate per-protocol settings for SMB and NFS encryption, which it does not evaluate.

Data in transit at risk; nothing to save

There is no saving attached. The exposure is credentials and data readable or modifiable in transit by anyone between the client and Azure.

Requiring HTTPS again

  1. Find clients still using http:// endpoints in logs or configuration and switch them to https://.
  2. Turn the requirement on: az storage account update --resource-group my-rg --name mystorage --https-only true.
  3. Retest applications, especially older tools and scripts.
  4. For Azure Files over SMB, note that unencrypted SMB connections (SMB 2.1, or SMB 3.x without encryption) fail when secure transfer is required, unless per-protocol settings say otherwise.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·