<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Entra ID on Cloudkaramchari</title><link>https://www.cloudkaramchari.com/tags/entra-id/</link><description>Recent content in Entra ID on Cloudkaramchari</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>cloudkaramchari</copyright><lastBuildDate>Mon, 14 Sep 2026 18:30:00 +0530</lastBuildDate><atom:link href="https://www.cloudkaramchari.com/tags/entra-id/index.xml" rel="self" type="application/rss+xml"/><item><title>Azure User-Bound Delegation SAS Is GA: Lock Storage Tokens to a Single Entra Identity</title><link>https://www.cloudkaramchari.com/blog/azure-user-bound-delegation-sas-setup-guide/</link><pubDate>Mon, 14 Sep 2026 18:30:00 +0530</pubDate><guid>https://www.cloudkaramchari.com/blog/azure-user-bound-delegation-sas-setup-guide/</guid><description>
&lt;h1 id="azure-user-bound-delegation-sas-is-ga-lock-storage-tokens-to-a-single-entra-identity">Azure User-Bound Delegation SAS Is GA: Lock Storage Tokens to a Single Entra Identity&lt;/h1>
&lt;p>Every SAS token you've ever generated for Azure Storage has the same underlying weakness: it's a bearer credential. Whoever holds the URL — the person you sent it to, whoever they forwarded it to, whoever it leaked to in a log line or a Slack message or a public GitHub gist — can use it, for as long as it's valid, with no way for Azure to tell the difference between the intended recipient and anyone else holding the string. A 7-day user delegation SAS &amp;quot;expiring soon&amp;quot; is cold comfort if it's been sitting in a misconfigured public bucket for six of those days.&lt;/p></description></item></channel></rss>