Skip to content

Commit

Permalink
Patch 522 (#543)
Browse files Browse the repository at this point in the history
* Update queue-service-all-access-acl.md

* UPDATED ALL STEPS IMAGES

* Update queue-service-all-access-acl.md

* Apply suggestions from code review

Co-authored-by: alphadev4 <[email protected]>
  • Loading branch information
shuklaalok87 and alphadev4 authored Oct 25, 2022
1 parent 80bf406 commit afee2ec
Show file tree
Hide file tree
Showing 12 changed files with 8 additions and 11 deletions.
18 changes: 8 additions & 10 deletions en/azure/queueservice/queue-service-all-access-acl.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,14 +17,12 @@
## Detailed Remediation Steps

1. Log into the Microsoft Azure Management Console.
2. Select the "Search resources, services, and docs" option at the top and search for Storage account. </br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step2.png"/>
2. In the search bar at the top search for Storage and select "Storage accounts" from the result. </br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step2.png"/>
3. Select the "Storage account" by clicking on the "Name" link to access the configuration changes. </br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step3.png"/>
4. Click on the "Overveiw" in the selected "Storage account" and scroll down the right side of the settings and click on the "Queues" option under "Services".</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step4.png"/>
5. Select the "Queue" by clicking on the "Name" link to access the configuration changes. </br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step5.png"/>
6. In the selected "Queue", click on the "Access Policy" and check the "Permissions" assosciated with the "Queue". If the "Queue" allows full write, delete, or read ACL permissions then the selected "Queue" is not as per the standard configurations.</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step6.png"/>
7. Repeat steps number 2 - 6 to verify other "Queues" in the Azure account. </br>
8. Navigate to the "Storage accounts", select the "Storage account" and click on the "Name", select the "Overview" options and select the "Queue" by clicking on the "Name" as a link to access the configurations.</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step8.png"/>
9. On the "Queue" configuration click on the "Access Policy" option and select the "Edit" option to make the changes.</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step9.png"/>
10. Uncheck the global read/write/detele policies under the "Permissions" and click on the "OK" button to make the changes.</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step10.png"/>
11. Click on the "Save" button at the top to save the configuration changes.</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step11.png"/>
12. Repeat steps number 8 - 11 to ensures "Queues" do not allow full write, delete, or read ACL permissions.</br>
4. In the left navigation panel, scroll down and click on the "Queues" option under "Data storage".</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step4.png"/>
5. Select the "Queue" by clicking on the triple dots (...) at the end of the row and click "Access policy". </br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step5.png"/>
6. On the "Access Policy" panel check the "Permissions" associated with the "Queue". If it says "raup" then the queue allows full write, delete, or read ACL permissions and is not as per the security recommendations.</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step6.png"/>
7. Click the triple dots (...) and click "Edit" option to make changes.</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step7.png"/>
8. In the "Edit policy" pop up that opens, click the "Permissions" dropdown, uncheck the global read and update policies, then click on the "OK" button to save the changes.</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step8.png"/>
9. Click on the "Save" button at the top to save the configuration changes.</br> <img src="/resources/azure/queueservice/queue-service-all-access-acl/step9.png"/>
12. Repeat step number 4 - 9 to check all other "Queues" do not allow full write, delete, or read ACL permissions.</br>

This file was deleted.

Binary file not shown.
Binary file not shown.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.

0 comments on commit afee2ec

Please sign in to comment.