Destination Setup
Azure Blob Storage
Configuring your Azure Blob Storage destination.
Step 1: Create Azure storage account
- In the Azure portal, navigate to the Storage accounts service and click + Create.
- In the “Basics” tab of the “Create a storage account” form, fill in the required details.
- In the “Advanced” settings, under “Security” make sure Enable storage account key access is turned on. You may turn off (deselect) “Allow enabling public access on containers”. Under “Data Lake Storage Gen2”, select Enable hierarchical namespace.
Enable hierarchical namespace and other settings
- In the “Networking” settings, you may limit “Network access” to either Enable public access from all networks or Enable public access from selected virtual networks and IP addresses. If the latter is selected, be sure to add the service’s static IP to the address range of the chosen virtual network. All other settings can use the default selections.
- In the “Data protection” settings, you must turn off Enable soft delete for blobs, Enable soft delete for containers, and Enable soft delete for file shares.
Disable default soft delete settings
- Once the remaining options have been configured to your preference, click Create.
Step 2: Create container and access token
- In the Azure portal, navigate to the Storage accounts service and click on the account that was created in the previous step.
- In the navigation pane, under “Data storage”, click Containers. Click + Container, choose a name for the container, and click Create.
- In the navigation pane, under “Security + networking”, click Shared access signature.
- Update the required accessible services and permissions:
- Under “Allowed services”: select Blob and File.
- Under “Allowed resource types”: select Container and Object.
- Under “Allowed permissions”: select Read, Write, Delete, List, Add, Create, and Permanently Delete.
- Select a “Start and expiry date/time” based on your security posture (e.g., set the expiration date 6 months into the future), and click Generate SAS and connection string.
- Make a note of the SAS token that is generated.
Generate SAS token and connection string
Step 3: Add your destination
Securely share your storage account name, container name, your chosen folder name for the data, and your Storage account SAS token with us to complete the connection.