Secure downloads and uploads of Azure managed disks

If you use Microsoft Entra ID to control resource access, you can also use it to restrict uploads and downloads of Azure managed disks. When a user tries to upload or download a disk, Azure validates the identity of the requesting user in Microsoft Entra ID, and confirms that user has the required permissions. If a user doesn't have the required permissions, they can't upload or download managed disks.

At a higher level, a system administrator can set a policy at the Azure account or subscription level, to ensure that all disks and snapshots must use Microsoft Entra ID for uploads or downloads. If you have any questions on securing uploads or downloads by using Microsoft Entra ID, reach out to: azuredisks@microsoft .com.

Restrictions

  • VHDs can't be uploaded to empty snapshots.
  • Azure Backup doesn't currently support disks secured with Microsoft Entra ID.
  • Azure Site Recovery doesn't currently support disks secured with Microsoft Entra ID.

Prerequisites

Install the latest Azure PowerShell module or the latest Azure CLI.

Assign an Azure RBAC role

To access managed disks secured by using Microsoft Entra ID, users must have either the Data Operator for managed disks role assigned through Azure role-based access control (Azure RBAC) or a custom role with the following permissions:

  • Microsoft.Compute/disks/download/action
  • Microsoft.Compute/disks/upload/action
  • Microsoft.Compute/snapshots/download/action
  • Microsoft.Compute/snapshots/upload/action

For detailed steps on assigning a role, see the following articles for Azure portal, Azure PowerShell, or Azure CLI. To create or update a custom role, see the following articles for Azure portal, Azure PowerShell, or Azure CLI.

Restrict access to an individual disk

To restrict access to an individual disk, enable data access authentication mode on that disk.

You can enable this setting when creating the disk, or you can enable it on the Disk Export page under Settings for existing disks.

Screenshot of the Disk Export pane with Enable data access authentication mode selected and Save highlighted.

Create an Azure Policy assignment

You can also create an Azure Policy assignment with a remediation task. A policy assignment with a remediation task continuously audits your resources and notifies you when any of them don't comply. Use the built-in policy definition Protect your data with authentication requirements when exporting or uploading to a disk or snapshot. To learn how to create an Azure Policy assignment, see the Azure portal, Azure CLI, or Azure PowerShell articles.

Next steps