Views:
File Security Storage provides easy deployment using Cloud Account Management Terraform to integrate automated scanning of files as you upload them into your Azure storage accounts and effortlessly detect all types of malware including viruses, trojans, spyware, and more.
You deploy File Security Storage using the Cloud Account Management Terraform template. After deploying the File Security Storage scanner stack to your Cloud Account Management region and turning on scanning for selected storage accounts in that region, the scanner stack scans all incoming files. It does not, however, scan files that are currently in the storage account.
Note
Note
The Scanner stack is deployed in the same region as the storage account it scans (1:1 regional mapping). Each scanner stack only scans storage accounts in its own region.

Supported storage account types

File Security Storage uses Azure Event Grid to detect files as they are uploaded, so it can only scan storage accounts that support Event Grid.
  • Standard general-purpose v2 (StorageV2): Supported.
  • General-purpose v1: Not supported. General-purpose v1 storage accounts do not support Event Grid. If you turn on scanning for a general-purpose v1 storage account, the operation fails with error code 3303405.
To scan a general-purpose v1 storage account, first upgrade it to general-purpose v2 in the Azure portal.
The following architecture diagram illustrates the main File Security Storage information flow for Azure.
fss-azure-architecture=4b7e01ca-8253-49cc-b99c-250ae5cba06b.png