In the previous example, the PowerShell script was available for download by anyone who possessed its URL. This is not an ideal situation from a security standpoint. The scripts should only be accessible and downloadable by authorized users. Fortunately, the content of an Azure Storage account can be protected by changing its access policy from anonymous access to private access. In such a case, a special token is needed to access the contents of the storage container, as shown in the following screenshot:
An SAS token can be generated for any storage account with the necessary permissions for a particular time period, and can also be used in ARM templates to download Custom Script Extensions and PowerShell scripts, as shown in the following screenshot:
The code file WindowsVirtualMachine-Protected.json shows the usage of an SAS token within...