Pair of 512-bit keys belonging to a storage account; every account SAS and service SAS is signed with one of them. Once both are regenerated, direct key access and all those SAS tokens stop working.
Also called storage account keys.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Access keys in context, with comparison tables and the common traps.
Terms in this definition
- Storage account
The top-level resource in Azure Storage, giving a unique namespace for table, queue, file and blob data. Location, performance and kind are set when it is created and cannot change.
- Account SAS
Shared access signature created with an account key. One token may cover multiple services (ss), resource types (srt) and permissions (sp), service-level operations included, but turning off Shared Key authorisation blocks it.
- Service SAS
Delegates access to just one storage service, a container for instance, using a signature made with the account key. Disabling Shared Key breaks it; it may refer to a stored access policy.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
- Serial Attached SCSI
SAS for short: the interface typically found on server drives and shared JBOD enclosures; Storage Spaces handles it alongside NVMe and SATA. Don't mix it up with Azure's shared access signatures.
- Stop sequence
One of up to four strings that make the model halt generation; the sequence itself is not included in the output.
Related terms
- Key Vault managed storage account keys
Older Key Vault capability for storing storage account keys and regenerating them on a schedule. Microsoft Entra ID authorisation for storage has replaced it.
- Keys and Endpoint
Page in the Azure portal for an Azure OpenAI or Foundry Tools resource, listing the resource's REST endpoint together with its two access keys, Key1 and Key2.
- listKeys action
Running
Microsoft.Storage/storageAccounts/listKeys/action, a control-plane action, hands back the storage account keys. Anyone with it therefore has full Shared Key access to data, data actions or not. - Reader and Data Access
Storage role allowing a user to see storage accounts and retrieve their access keys (
listKeysandListAccountSas) so data can be read with Shared Key. Regenerating keys is not permitted.