A shared access signature (SAS) is a signed URL query string that grants limited, time-bound access to storage resources without sharing an account key or requiring the client to have an Entra identity. It is typical for letting a browser upload a file directly, or giving a partner temporary read access to one container. The token encodes permissions (read, write, list, delete and so on), a start and expiry time, the resource, and optionally allowed IP addresses and protocol (HTTPS only), then a signature proves it was issued by someone with the right to do so.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.