Delegates access to just one storage service, a container for instance, using a signature made with the account key. Disabling Shared Key breaks it; it may refer to a stored access policy.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Service SAS in context, with comparison tables and the common traps.
Terms in this definition
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Shared Key
For storage, signing requests with one of two 512-bit account keys; this bypasses RBAC and opens every service fully unless Shared Key is disabled. In VPN Gateway the term means the pre-shared secret entered on the peer device and on an S2S or VNet-to-VNet connection.
- Stored access policy
A policy on a container that limits, and allows revocation of, every service SAS pointing to it. It grants no access itself, a container can hold at most five, and user delegation SAS cannot use it.
Related terms
- Access keys
Pair of 512-bit keys belonging to a storage account; every account SAS and service SAS is signed with one of them. Once both are regenerated, direct key access and all those SAS tokens stop working.
- Allow storage account key access
Storage setting which, once disabled, makes every request authorised by Shared Key fail with 403, covering account keys plus account and service SAS. Microsoft Entra identities gain nothing from it, and user delegation SAS keeps working.