You have an Azure subscription containing a storage account named storage1 and two web apps named app1 and app2.
storage1
app1
app2
Both apps will write data to storage1.
You need to ensure that each app can read only the data it wrote.
What should you do?
A system-assigned managed identity gives each web app its own Microsoft Entra security principal. Azure Storage can use Microsoft Entra authentication and Azure RBAC to grant each identity access only to that app’s permitted data scope. Storage account keys provide account-level Shared Key access, so separate keys do not isolate the apps’ data.
Community Discussion