Is there a way to find out the actual creation time of an access policy?

Viewed 25

I've got a container in a storage account. An access policy has been added programmatically with a start time (in the past) and an expiry time (in the future). I can view these in the portal. However, is there a way to actually seen when the access policy was created?

The reason for wanting to know this is that occasionally during load testing I'm getting a 403 when trying to download from the container. I suspect this is because the access policy hasn't actually been created at that point, which means the SAS token won't work, but I'd like to be able to confirm that.

1 Answers

However, is there a way to actually seen when the access policy was created?

It is not possible to do so.

One solution to your problem is to look at error details when the download fails with 403 error. Azure Storage Service will tell you why the operation failed.

For example, when I try to download a blob using a SAS URL created with a non-existing access policy, I get the following error back:

<?xml version="1.0" encoding="UTF-8"?>
<Error>
   <Code>AuthenticationFailed</Code>
   <Message>Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature.
RequestId:a3b89d43-a2fd-9bc3-9da4-3f1fa8b9e5a7
Time:2022-08-17T12:50:25.7680928Z</Message>
   <AuthenticationErrorDetail>SAS identifier cannot be found for specified signed identifier</AuthenticationErrorDetail>
</Error>

As you can see, the AuthenticationErrorDetail clearly tells you that the operation failed because the access policy does not exist.

Related