For storage, signing requests with one of two 512-bit account keys; this bypasses RBAC and opens every service fully unless Shared Key is disabled. In VPN Gateway the term means the pre-shared secret entered on the peer device and on an S2S or VNet-to-VNet connection.
Also called account access key.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Shared Key in context, with comparison tables and the common traps.
Terms in this definition
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - RBAC
Short for role-based access control: Azure role assignments, inherited downward through scopes, that decide who may perform which actions on resources. Resource location and size are outside its control.
- VPN gateway
Terminates IPsec tunnels for site-to-site, point-to-site and VNet-to-VNet connections, as a VPN-type virtual network gateway in GatewaySubnet. It gets a Standard static public IP when created, and that IP can't be swapped.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
- S2S
Connects an entire on-premises office or datacentre to an Azure virtual network through an encrypted IPsec/IKE tunnel running between a local VPN device and an Azure VPN gateway.
- VNet-to-VNet connection
An IPsec/IKE link joining two Azure VPN gateways. Turning on BGP for it lets chained VNets and sites exchange their prefixes.
Related terms
- Account SAS
Shared access signature created with an account key. One token may cover multiple services (ss), resource types (srt) and permissions (sp), service-level operations included, but turning off Shared Key authorisation blocks it.
- Allow storage account key access
Storage setting which, once disabled, makes every request authorised by Shared Key fail with 403, covering account keys plus account and service SAS. Microsoft Entra identities gain nothing from it, and user delegation SAS keeps working.
- Group by (Power Query)
Collapsing rows by shared key values is what this Power Query step does, returning one row for each group together with summary columns, for example a count of rows, a sum or all the grouped rows. Fuzzy grouping is limited to Power Query Online.
- listKeys action
Running
Microsoft.Storage/storageAccounts/listKeys/action, a control-plane action, hands back the storage account keys. Anyone with it therefore has full Shared Key access to data, data actions or not. - Reader and Data Access
Storage role allowing a user to see storage accounts and retrieve their access keys (
listKeysandListAccountSas) so data can be read with Shared Key. Regenerating keys is not permitted. - Service SAS
Delegates access to just one storage service, a container for instance, using a signature made with the account key. Disabling Shared Key breaks it; it may refer to a stored access policy.
- Storage Account Contributor
Manages storage accounts at the management plane, yet because listKeys is among its permissions it can reach every piece of data via Shared Key. For data access, that is broader than least privilege.
- Storage Account Key Operator Service Role
Can list and regenerate a storage account's keys; since those keys work with Shared Key, holders can effectively reach all of the account's data.