A policy on a container that limits, and allows revocation of, every service SAS pointing to it. It grants no access itself, a container can hold at most five, and user delegation SAS cannot use it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Stored access policy in context, with comparison tables and the common traps.
Terms in this definition
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- Service SAS
Delegates access to just one storage service, a container for instance, using a signature made with the account key. Disabling Shared Key breaks it; it may refer to a stored access policy.
- User delegation SAS
The most secure kind of SAS, signed using Microsoft Entra credentials, so it still works when Shared Key is disabled. Valid for up to 7 days, it covers Blob (ADLS Gen2 included), Queue, Table and Azure Files over REST, but not stored access policies.