Azure storage accounts that accept REST requests over plain HTTP
What does ZopNight detect here?
ZopNight flags a storage account whose `enableHttpsTrafficOnly` (secure transfer required) setting is false, which lets REST calls to blobs, queues, tables and files arrive over plain HTTP. Azure enables secure transfer by default on new accounts, so a finding means it was turned off. Severity is high and no saving is claimed.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1322 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | enableHttpsTrafficOnly = false |
| Source | ZopNight |
| Permissions used | Microsoft.Storage/storageAccounts/read |
Where it applies
Secure transfer is on by default for a reason
When secure transfer is required, every call to an Azure Storage REST API operation must use HTTPS and any HTTP request is rejected. Microsoft enables the property by default when an account is created.
Turn it off and requests carrying authorization headers, SAS tokens in URLs and the data itself can travel unencrypted. Anyone on the network path can read or alter them.
Listing accounts that allow HTTP
az storage account list \ --query "[?enableHttpsTrafficOnly==\`false\`].{name:name, rg:resourceGroup}" -o tableEach row is an account where the secure transfer requirement is off.
The property behind the finding
ZopNight reads the account’s secure-transfer setting from Azure and fires when it is explicitly false. It is a configuration read with no metric or window, repeated every scan, and cleared as soon as Azure reports the setting on.
Accounts that are not flagged
If the setting was not returned for an account, ZopNight treats it as unknown and raises no finding. Tags on the account are not consulted. This check looks only at REST traffic; Azure Files now has separate per-protocol settings for SMB and NFS encryption, which it does not evaluate.
Data in transit at risk; nothing to save
There is no saving attached. The exposure is credentials and data readable or modifiable in transit by anyone between the client and Azure.
Requiring HTTPS again
- Find clients still using
http://endpoints in logs or configuration and switch them tohttps://. - Turn the requirement on:
az storage account update --resource-group my-rg --name mystorage --https-only true. - Retest applications, especially older tools and scripts.
- For Azure Files over SMB, note that unencrypted SMB connections (SMB 2.1, or SMB 3.x without encryption) fail when secure transfer is required, unless per-protocol settings say otherwise.