Security
4 posts tagged “Security”.
May 2026
-
Share blobs with user delegation SAS tokens
A SAS token signed with the storage account key can't be revoked without rotating the key. A user delegation SAS is signed with Entra ID credentials, expires sooner and fits with managed identity.
January 2026
-
Receiving webhooks safely
A webhook endpoint is a public URL that anyone can call. Verify the signature, reject replays, respond quickly and expect duplicates.
December 2025
-
Key Vault references in App Service and Functions
Keep secrets in Key Vault without changing a line of code. App settings can point at a secret, and your app reads it like any other setting.
October 2025
-
Use managed identity instead of connection strings
Connection strings with keys end up in config files, pipelines and screenshots. Managed identity lets your Azure app authenticate with no secret at all.