Managed Identity read access to Azure Storage Blob & Table with PowerShell

Viewed 193

I've been trying to get access to a storage blob (and table in future) with a managed identity in Azure Automation, but unfortunately I can't get it to work.

The Managed Identity has the following permissions on the Blob:

  • Contributor
  • Managed Application Operator Role
  • Storage Blob Data Contributor
  • Storage Table Data Contributor

I've tried several resources to get my accesstoken:

  • 'https://storage.azure.com/'
  • 'https://STORAGE.blob.core.windows.net/'

I do get the AccessToken for both resources, yet I still get the famous 403 forbidden errors.

This is the Uri I use to access the blob:

'https://{0}.blob.core.windows.net/{1}{2}' -f $($Storage), $Container, $FileName

My invoke uses the Get method:

 $InvokeSplatting = @{
            Uri = $Uri
            Method = 'Get'
            headers = $Headers
        }

The header contains the AccessToken: "Bearer ~"

Am I doing something wrong?

PS: the script did work with a SASToken, so something must be up with the AccessToken.

function New-ManagedIdentityAccessToken {
    <#
    .SYNOPSIS
    Short description
    
    .DESCRIPTION
    Resources:
    'https://vault.azure.net'
    'https://management.azure.com'
    'https://storage.azure.com/'
    
    .PARAMETER Resource
    Parameter description
    
    .EXAMPLE
    An example
    
    .NOTES
    General notes
    #>
    [CmdletBinding()]
    param (
        [parameter(mandatory = $true)]
        $Resource
    )
    begin {
        $url = $env:IDENTITY_ENDPOINT  
        $headers = New-Object "System.Collections.Generic.Dictionary[[String],[String]]" 
        $headers.Add("X-IDENTITY-HEADER", $env:IDENTITY_HEADER) 
        $headers.Add("Metadata", "True") 
        $body = @{resource = $Resource }
    }
    process {
        $accessToken = Invoke-RestMethod $url -Method 'POST' -Headers $headers -ContentType 'application/x-www-form-urlencoded' -Body $body 
        $Headers = @{
            Authorization = "Bearer $($accessToken.access_token)"
        }
    }
    end {
        return $Headers
    }
}
0 Answers
Related