Detecting SAS Token Exposure: Defender for Cloud and Sentinel KQL
Retrospective: this article looks back at events from September 2023, written in 2026 with the benefit of hindsight.
Overly permissive or leaked SAS tokens provide direct access to Azure Storage. These detections help find token exposure and misuse.
Signals worth watching
- Storage requests authenticated with SAS from unfamiliar IP addresses.
- SAS-authenticated requests that write or delete data unexpectedly.
- Large downloads using SAS tokens.
- SAS tokens with long expiry detected in code repositories (GitHub secret scanning alerts).
- Storage account key regeneration or listing by unexpected identities.
- Defender for Storage alerts.
Where the data lives
- StorageBlobLogs (and file/queue/table logs):
AuthenticationTypeshows SAS, AccountKey, OAuth or Anonymous. - Azure Activity logs:
listKeys,regenerateKey. - GitHub secret scanning alerts.
- Defender for Storage alerts.
A starting query
SAS-authenticated access by caller IP:
StorageBlobLogs
| where AuthenticationType == "SAS"
| summarize Requests = count(), Writes = countif(OperationName in ("PutBlob", "DeleteBlob", "PutBlock")),
Bytes = sum(ResponseBodySize) by AccountName, CallerIpAddress, bin(TimeGenerated, 1h)
| sort by Bytes desc
Response
- Revoke the token: for account or service SAS, rotate the storage account key (and update legitimate consumers); for user delegation SAS, revoke user delegation keys.
- Review accessed and modified data.
- Check integrity of data that may have been modified, such as AI models or software packages.
- Remove exposed tokens from repositories and history.
- Microsoft AI Researchers Expose 38TB via an Overly Permissive SAS Token (Sept 2023) Incident Teardowns
- How to Govern Azure Storage SAS Tokens and Disable Shared Key Access How-To & Hardening
- CIO Brief: AI Projects Create New Data Exposure Paths CIO Briefings