New Attribute-Based Access Control for Blob

  Рет қаралды 7,110

John Savill's Technical Training

John Savill's Technical Training

Күн бұрын

Пікірлер: 13
@iamdedlok
@iamdedlok 3 жыл бұрын
Good stuff! Thanks John, this looks like a very powerful feature! Great coverage.
@jlou65535
@jlou65535 3 жыл бұрын
Thanks John, well explained as usual
@h198xb
@h198xb 3 жыл бұрын
Great write-up. I wonder could it be a solution for authorising access with frequently changing levels: so we have a data storage and all users have read access role. But we add a per-user condition and assign index tag, when we want to allow a user access specific blob.... Would it work? What are the restrictions on number of tags in user assignment? (so can we dynamically add 100/500 tags to a user assignment?) How is it encoded in access token (or is it evaluated in the backend?)? If we need to provide an URL-based access to the data, is it feasible to have a service, requesting the blob content on behalf of the user via rest api and presenting it via an url? or is there any better way? Or may be you can share name of the PM of the feature so I could try to find answers there..
@jackgleeson8321
@jackgleeson8321 3 жыл бұрын
This is very interesting thanks for making the video.
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Glad it was helpful!
@satya2943
@satya2943 3 жыл бұрын
Thank you John..!!
@flymetothemoon5138
@flymetothemoon5138 3 жыл бұрын
Could you combine this with AAD B2C to control blob access and restrict to B2C users?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Subscriptions can't trust B2C instances for RBAC, only regular AAD. For B2C based apps would likely be more of a valet pattern.
@stephane184
@stephane184 3 жыл бұрын
Game changer indeed. Unfortunately, seems for me, the option to use tags as condition is not yet available. I dont see it in the drop down of choices of attributes. Only account name, container name or blob path. :-( Hopefully it'll be available soon.
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
That does not sound right. Check all the settings match mine and its GPv2 storage account (which is what mine was)
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
docs.microsoft.com/en-us/azure/storage/blobs/storage-manage-find-blobs?tabs=azure-portal#regional-availability-and-storage-account-support. You may need to register sub for the blob index
@stephane184
@stephane184 3 жыл бұрын
Possible it’s because I didn’t use Blob Storage Data Owner as the role. I think I recall you mentioned something about that. I was able to see the blob tags condition when I used storage data owner role. 😎
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
@@stephane184 yes only owner can set tags
Azure Blob Data Permissions Deep Dive (360 in 360)
30:01
John Savill's Technical Training
Рет қаралды 20 М.
Каха и дочка
00:28
К-Media
Рет қаралды 1,7 МЛН
It’s all not real
00:15
V.A. show / Магика
Рет қаралды 13 МЛН
Azure Resource Mover - Move resources between regions, subscriptions and resource groups
23:22
John Savill's Technical Training
Рет қаралды 23 М.
Understanding Attribute Based Access Control (ABAC)
20:28
All Things IAM
Рет қаралды 16 М.
Azure Data Lake Storage Gen 2 Overview
20:32
John Savill's Technical Training
Рет қаралды 29 М.
ABAC and RBAC in Azure
10:33
Patrik's Tech Lightning
Рет қаралды 2,9 М.
Protecting Your Environment
52:24
John Savill's Technical Training
Рет қаралды 9 М.
ABAC 101 Attribute Based Access Control CISSP CSSLP CCSP
22:14
Prabh Nair
Рет қаралды 14 М.
Azure Storage Data Role Based Access Control
13:35
John Savill's Technical Training
Рет қаралды 11 М.
Azure Managed Disks Deep Dive
57:39
John Savill's Technical Training
Рет қаралды 19 М.
Picking the right Azure Load Balancing Solution
42:28
John Savill's Technical Training
Рет қаралды 45 М.
Easily create ABAC policies with the Permit UI - Tutorial
11:15