Storage baseline is somewhat simple and has the majority of the secure policy enabled by default. Although it’s enabled, it’s always best to double check and understand what is enabled.
If you want more information, I’ve covered all the security features here:
https://securethelogs.com/securing-storage-accounts/
The only exception which isn’t mentioned is as followed:
Public & Private Access To Blob Containers
There is an option to enable your Blob container to have Public or Private access. By default, the blob will only have the permissions which have been already set.
There may be a need for you to allow access to certain data without having to share account keys or require authentication. This is when you would select Public Access Level. This would grant anonymous users read only access at a Public level.
Because this will be highly unlikely and less secure, it’s better to set it to Private.
To do so, click Change Access Level above whilst inside the Blob container:
