How to disable SAS token on consumption/Premium plan hosted function apps by info.odysseyx@gmail.com August 26, 2024 written by info.odysseyx@gmail.com August 26, 2024 0 comment 6 views 6 As you may know, Azure Files currently does not support identity-based connections. This means that even if you can use identity-based host connections to replace AzureWebjobsStorage, which uses SAS tokens, you cannot remove the file share connection string (WEBSITE_CONTENTAZUREFILECONNECTIONSTRING) that relies on SAS tokens. Therefore, you cannot disable SAS tokens on your storage account. Now, when creating a function app in a Consumption/EP plan, you have the option to create the app without Azure Files. This scenario allows you to bypass the SAS token requirement for Azure Files and access the storage account using only managed identities. To run your app without relying on an Azure file share, you must meet the following requirements: 1. Deploy the package to a remote Azure Blob storage container.2. Set the URL that grants access to the package in the WEBSITE_RUN_FROM_PACKAGE app setting.This method allows you to store your app content in Blob storage that supports managed identities instead of Azure Files. Now let’s look at how to change the file share and SAS token connection in the Consumption/EP function app. 1. To create a function app without a file share, you can uncheck the “Add an Azure Files connection” option in the “Storage” panel when creating a function app through the Azure portal. 2. After creation, go to the Functions app and activate the ID assigned to the system. 3. Go to your Storage account and go to IAM. Assign the Storage Blob Data Contributor role to your function app. 4. Create a new blob container to store the zip package of your function app and copy the URL of the file. 5. Now go back to your function app and replace the SAS token. Go to Environment Variables and change AzureWebJobsStorage to AzureWebJobsStorage__accountname and set its value to your storage account name. Then set the app to run from a URL by adding an app setting WEBSITE_RUN_FROM_PACKAGE and setting its value to the file URL you copied in the previous step. 6. When specifying a URL to read from the app, you must manually sync the trigger after publishing the updated package. You can sync the trigger using one of the following methods: Restart the function app in the Azure portal. Send an HTTP POST request https://{functionappname}.azurewebsites.net/admin/host/synctriggers?code= By using master key. Send an HTTP POST request https://management.azure.com/subscriptions//resourceGroups//providers/Microsoft.Web/sites//syncfunctiontriggers?api-version=2016-08-01. Replace the placeholders with your subscription ID, resource group name, and function app name. This request requires: Access Token at Authorization Request Header. Source link Share 0 FacebookTwitterPinterestEmail info.odysseyx@gmail.com previous post Exploring the latest AI features in Clipchamp next post Create neat lines and shapes with ink in Word for Windows You may also like Azure API Management Circuit Breaker and Load Balancing September 10, 2024 Microsoft at Open Source Summit Europe 2024 September 9, 2024 LLM Load Testing on Azure (Serverless or Managed-Compute) September 9, 2024 Day zero support for iOS/iPadOS 18 and macOS 15 September 9, 2024 Oracle Database@Azure, Microsoft Fabric, GoldenGate, Oracle September 9, 2024 Oracle Database@Azure, Australia east, Oracle, Azure, Data, AI September 9, 2024 Leave a Comment Cancel Reply Save my name, email, and website in this browser for the next time I comment.