What is the best maximum time we can limit the SAS URL expiry date?

Rajoli Hari Krishna 636 Reputation points
2025-03-04T06:07:40.4+00:00

Hi MS Team,

We have migrated our Azure Subscription Resources to Azure Landing Zone Subscription and all the web apps are connecting to the storage account using SAS URL with some limitation on the permission wise and the expiry time limit.

Earlier We use to generate the SAS URL for every 6 months/1 year but now the dev team is asking us to generate the SAS tokens more than 6 months i.e., 10 years.

Is that safer to generate the SAS URL/token for more than 6 months or a year?

Note: Our Landing Zone Resources are disabled with public network access and enabled with private endpoint and only the authorized clients and office staff would be eligible to access the web app/sites so there were many places we used different storage accounts SAS URLs/tokens in the web application for the secure data transfer and communication purpose.

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,399 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Abiola Akinbade 23,770 Reputation points
    2025-03-04T07:48:06.73+00:00

    Hello Rajoli Hari Krishna,

    Thanks for your question.

    There is no hard limit on SAS expiry.

    It’s advisable to set the shortest feasible expiration time for SAS tokens to reduce potential exposure if a token is compromised. It’s prudent to also follow least privilege, limiting both the permissions and the validity period of SAS tokens.

    This is a general security practice. I will refer you to your companies policies regarding secrets and tokens.

    You can mark it 'Accept Answer' and 'Upvote' if this helped you

    Regards,

    Abiola

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.