Shared access signature created with an account key. One token may cover multiple services (ss), resource types (srt) and permissions (sp), service-level operations included, but turning off Shared Key authorisation blocks it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Account SAS in context, with comparison tables and the common traps.
Terms in this definition
- Shared access signature
A signed token that delegates storage access for a limited time. It is a signature rather than a role assignment, and it does not apply to SMB.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Shared Key
For storage, signing requests with one of two 512-bit account keys; this bypasses RBAC and opens every service fully unless Shared Key is disabled. In VPN Gateway the term means the pre-shared secret entered on the peer device and on an S2S or VNet-to-VNet connection.
- Authorisation
Working out which actions and data a signed-in user or application is permitted, typically via role assignments. It comes after authentication.
Related terms
- Access keys
Pair of 512-bit keys belonging to a storage account; every account SAS and service SAS is signed with one of them. Once both are regenerated, direct key access and all those SAS tokens stop working.