The most secure kind of SAS, signed using Microsoft Entra credentials, so it still works when Shared Key is disabled. Valid for up to 7 days, it covers Blob (ADLS Gen2 included), Queue, Table and Azure Files over REST, but not stored access policies.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains User delegation SAS in context, with comparison tables and the common traps.
Terms in this definition
- HTTP / HTTPS
The protocols of the web, with HTTPS being HTTP secured by TLS.
- Serial Attached SCSI
SAS for short: the interface typically found on server drives and shared JBOD enclosures; Storage Spaces handles it alongside NVMe and SATA. Don't mix it up with Azure's shared access signatures.
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Shared Key
For storage, signing requests with one of two 512-bit account keys; this bypasses RBAC and opens every service fully unless Shared Key is disabled. In VPN Gateway the term means the pre-shared secret entered on the peer device and on an S2S or VNet-to-VNet connection.
- BLOB
Short for binary large object: raw binary data, like pictures, audio, video or documents, that only an application can make sense of. Azure keeps these files as blobs in Blob Storage.
- ADLS Gen2
Short for Azure Data Lake Storage Gen2: a standard GPv2 account with hierarchical namespace turned on, so analytics workloads get true directories and POSIX-style ACLs.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Azure Files
Azure's managed file shares over SMB or NFS. There is no Archive tier, and a single encryption key applies across the whole storage account.
Related terms
- Allow storage account key access
Storage setting which, once disabled, makes every request authorised by Shared Key fail with 403, covering account keys plus account and service SAS. Microsoft Entra identities gain nothing from it, and user delegation SAS keeps working.
- Storage Blob Delegator
A built-in role whose sole permission, at account scope or higher, is obtaining a user delegation key (generateUserDelegationKey) for signing a user delegation SAS. It gives no access to blob data.
- Stored access policy
A policy on a container that limits, and allows revocation of, every service SAS pointing to it. It grants no access itself, a container can hold at most five, and user delegation SAS cannot use it.