VM connecting to Storage account via Managed Identity(system-assigned).If permission removed,VM is able to transact against storage account.

Dave Norton 1 Reputation point
2021-08-30T12:07:15.33+00:00

We have picked up a behavior where a Virtual Machine with Windows Server 2019 is connecting to a Storage account with Blob Data Contributor rights via a Managed Identity(system-assigned). We have found when the permission is removed, the virtual machine is still able to transact against the storage account for some time afterwards. Is this expected? If so, are there any guidelines as to how long the permission propagation takes to come into effect? Is there a way to force the permission removal immediately?

Thanks.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,173 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,606 questions
{count} votes