A signed token that delegates storage access for a limited time. It is a signature rather than a role assignment, and it does not apply to SMB.
Also called SAS, SAS.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500AI-901AI-103AZ-900DP-750
Each book explains Shared access signature in context, with comparison tables and the common traps.
Terms in this definition
- Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - Role assignment
Gives access in Azure RBAC by binding three things together: who (a security principal), what (a role definition) and where (a scope).
- APPLY
Evaluates a table-valued expression for every row on its left, inside
FROM. Think ofOUTER APPLYas a left outer join andCROSS APPLYas an inner join. - SMB
Protocol for Windows file shares, used by Azure Files and supporting authentication based on identity.
Related terms
- Account SAS
Shared access signature created with an account key. One token may cover multiple services (ss), resource types (srt) and permissions (sp), service-level operations included, but turning off Shared Key authorisation blocks it.