# Storage Account

Source: /azure/services/storage-accounts/

## Introduction

An Azure storage account serves as a centralized container for all your data objects, including blobs, files, queues, and tables. It provides a unique, globally accessible namespace reachable via HTTP or HTTPS. For more information, see [Overview of storage accounts](https://learn.microsoft.com/en-us/azure/storage/common/storage-account-overview).

LocalStack for Azure provides a local environment for building and testing applications that make use of blobs, queues, and tables. For more information, see:

- [Blob Storage](/azure/services/blob-storage)
- [Queue Storage](/azure/services/queue-storage)
- [Table Storage](/azure/services/table-storage)

The supported APIs are available on our [API Coverage section](#api-coverage), which provides information on the extent of Storage Account's integration with LocalStack.

## Getting started

This guide is designed for users new to Azure Storage Accounts and assumes basic knowledge of the Azure CLI and our `lstk az` proxy.

Launch LocalStack using your preferred method. For more information, see [Introduction to LocalStack for Azure](/azure/getting-started/). Once the container is running, enable Azure CLI interception by running:

```bash
lstk az start-interception
```

This command points the `az` CLI away from the public Azure management REST API and toward the LocalStack for Azure emulator API.
To revert this configuration, run:

```bash
lstk az stop-interception
```

This reconfigures the `az` CLI to send commands to the official Azure management REST API.

### Create a resource group

Create a resource group for your storage account resources:

```bash
az group create \
  --name rg-storage-demo \
  --location westeurope
```

```bash title="Output"
{
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-storage-demo",
  "location": "westeurope",
  "managedBy": null,
  "name": "rg-storage-demo",
  "properties": {
    "provisioningState": "Succeeded"
  },
  "tags": null,
  "type": "Microsoft.Resources/resourceGroups"
}
```

### Create a storage account

Create a storage account with the `StorageV2` kind and `Standard_LRS` SKU:

```bash
az storage account create \
  --name stordoc86acct \
  --resource-group rg-storage-demo \
  --location westeurope \
  --sku Standard_LRS \
  --kind StorageV2
```

```bash title="Output"
{
  ...
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-storage-demo/providers/Microsoft.Storage/storageAccounts/stordoc86acct",
  ...
  "kind": "StorageV2",
  "location": "westeurope",
  "name": "stordoc86acct",
  ...
  "primaryEndpoints": {
    "blob": "https://stordoc86acct.blob.core.azure.localhost.localstack.cloud:4566",
    "queue": "https://stordoc86acct.queue.core.azure.localhost.localstack.cloud:4566",
    "table": "https://stordoc86acct.table.core.azure.localhost.localstack.cloud:4566",
    ...
  },
  "provisioningState": "Succeeded",
  ...
}
```

### Authentication

There are three ways to authenticate storage commands against the emulator:

#### Storage account key

Retrieve the account key and pass it with `--account-name` and `--account-key`:

```bash
ACCOUNT_KEY=$(az storage account keys list \
  --account-name stordoc86acct \
  --resource-group rg-storage-demo \
  --query "[0].value" \
  --output tsv)

az storage container list \
  --account-name stordoc86acct \
  --account-key "$ACCOUNT_KEY"
```

#### Login credentials

Use `--auth-mode login` to authenticate with the current session credentials:

```bash
az storage container list \
  --account-name stordoc86acct \
  --auth-mode login
```

#### Connection string

Bundle the account name and key into a single value:

```bash
CONNECTION_STRING=$(az storage account show-connection-string \
  --name stordoc86acct \
  --resource-group rg-storage-demo \
  --query connectionString -o tsv)

az storage container list \
  --connection-string "$CONNECTION_STRING"
```

The remaining examples in this guide use connection strings for brevity.

### Manage account keys and connection string

List the storage account access keys:

```bash
az storage account keys list \
  --account-name stordoc86acct \
  --resource-group rg-storage-demo
```

```bash title="Output"
[
  {
    "keyName": "key1",
    "permissions": "FULL",
    "value": "MWFjYTgyZjgtYzU0My00NjE0LThmZDctNzlkODg5ZjU4ZTE5",
    "..."
  },
  {
    "keyName": "key2",
    "permissions": "FULL",
    "value": "NzliNzVhN2EtYTcwZC00ZTg4LWJkMTQtYjg4MWNlMDJjZDcx",
    "..."
  }
]
```

Regenerate the primary key:

```bash
az storage account keys renew \
  --account-name stordoc86acct \
  --resource-group rg-storage-demo \
  --key key1
```

Fetch a connection string for data-plane operations:

```bash
az storage account show-connection-string \
  --name stordoc86acct \
  --resource-group rg-storage-demo
```

```bash title="Output"
{
  "connectionString": "DefaultEndpointsProtocol=https;EndpointSuffix=core.azure.localhost.localstack.cloud:4566;AccountName=stordoc86acct;AccountKey=YWQ5Y2Q2NDYtZTJmOC00ZjU3LWFmOTEtNzk5MjAxNzE1OWQx;BlobEndpoint=https://stordoc86acct.blob.core.azure.localhost.localstack.cloud:4566;FileEndpoint=https://stordoc86acct.file.core.azure.localhost.localstack.cloud:4566;QueueEndpoint=https://stordoc86acct.queue.core.azure.localhost.localstack.cloud:4566;TableEndpoint=https://stordoc86acct.table.core.azure.localhost.localstack.cloud:4566"
}
```

## Features

The Storage Account emulator supports the following features:

- **Control plane REST API**: Storage account CRUD (create, read, update, delete, list), account key management, and name availability checks via Azure Resource Manager.
- **Multiple authentication modes**: Storage account key, login credentials, and connection strings.
- **Storage account management**: Create, update, delete, and list storage accounts. Supports `StorageV2`, `BlobStorage`, and `Storage` account kinds with configurable SKU, access tier, and TLS version.
- **Account key management**: List and regenerate storage account keys (`key1`/`key2`).
- **Connection string generation**: Retrieve ready-to-use connection strings containing all service endpoints (Blob, Queue, Table, File).

## Limitations

- **Header validation**: Unsupported request headers or parameters are silently accepted instead of being rejected.
- **API version enforcement**: The emulator does not validate the `x-ms-version` header; all API versions are accepted.

## Samples

The following samples demonstrate how to use Storage Accounts with LocalStack for Azure:

- [Azure Functions Sample with LocalStack for Azure](https://github.com/localstack/localstack-azure-samples/tree/main/samples/function-app-storage-http/dotnet)
- [Azure Functions App with Managed Identity](https://github.com/localstack/localstack-azure-samples/tree/main/samples/function-app-managed-identity/python)
- [Azure Web App with Managed Identity](https://github.com/localstack/localstack-azure-samples/tree/main/samples/web-app-managed-identity/python)

## API Coverage


### Storage Account API coverage

Source service: `storage-accounts`. 9 of 70 tracked operations are implemented.

Service documentation: /azure/services/storage-accounts/

| Operation | Status |
| --- | --- |
| AdvancedPlatformMetrics.CreateOrUpdate | Not implemented |
| AdvancedPlatformMetrics.Delete | Not implemented |
| AdvancedPlatformMetrics.Get | Not implemented |
| AdvancedPlatformMetrics.List | Not implemented |
| BlobInventoryPolicies.CreateOrUpdate | Not implemented |
| BlobInventoryPolicies.Delete | Not implemented |
| BlobInventoryPolicies.Get | Not implemented |
| BlobInventoryPolicies.List | Not implemented |
| Connectors.Create | Not implemented |
| Connectors.Delete | Not implemented |
| Connectors.Get | Not implemented |
| Connectors.ListByStorageAccount | Not implemented |
| Connectors.TestExistingConnection | Not implemented |
| Connectors.Update | Not implemented |
| DataShares.Create | Not implemented |
| DataShares.Delete | Not implemented |
| DataShares.Get | Not implemented |
| DataShares.ListByStorageAccount | Not implemented |
| DataShares.Update | Not implemented |
| EncryptionScopes.Get | Not implemented |
| EncryptionScopes.List | Not implemented |
| EncryptionScopes.Patch | Not implemented |
| EncryptionScopes.Put | Not implemented |
| LocalUsers.CreateOrUpdate | Not implemented |
| LocalUsers.Delete | Not implemented |
| LocalUsers.Get | Not implemented |
| LocalUsers.List | Not implemented |
| LocalUsers.ListKeys | Not implemented |
| LocalUsers.RegeneratePassword | Not implemented |
| ManagementPolicies.CreateOrUpdate | Not implemented |
| ManagementPolicies.Delete | Not implemented |
| ManagementPolicies.Get | Not implemented |
| NetworkSecurityPerimeterConfigurations.Get | Not implemented |
| NetworkSecurityPerimeterConfigurations.List | Not implemented |
| NetworkSecurityPerimeterConfigurations.Reconcile | Not implemented |
| ObjectReplicationPolicies.CreateOrUpdate | Not implemented |
| ObjectReplicationPolicies.Delete | Not implemented |
| ObjectReplicationPolicies.Get | Not implemented |
| ObjectReplicationPolicies.List | Not implemented |
| PrivateEndpointConnections.Delete | Not implemented |
| PrivateEndpointConnections.Get | Not implemented |
| PrivateEndpointConnections.List | Not implemented |
| PrivateEndpointConnections.Put | Not implemented |
| PrivateLinkResources.ListByStorageAccount | Not implemented |
| StorageAccounts.AbortHierarchicalNamespaceMigration | Not implemented |
| StorageAccounts.CheckNameAvailability | Implemented |
| StorageAccounts.Create | Implemented |
| StorageAccounts.CustomerInitiatedMigration | Not implemented |
| StorageAccounts.Delete | Implemented |
| StorageAccounts.Failover | Not implemented |
| StorageAccounts.GetCustomerInitiatedMigration | Not implemented |
| StorageAccounts.GetProperties | Implemented |
| StorageAccounts.HierarchicalNamespaceMigration | Not implemented |
| StorageAccounts.List | Implemented |
| StorageAccounts.ListAccountSas | Not implemented |
| StorageAccounts.ListByResourceGroup | Implemented |
| StorageAccounts.ListKeys | Implemented |
| StorageAccounts.ListServiceSas | Not implemented |
| StorageAccounts.RegenerateKey | Implemented |
| StorageAccounts.RestoreBlobRanges | Not implemented |
| StorageAccounts.RevokeUserDelegationKeys | Not implemented |
| StorageAccounts.Update | Implemented |
| StorageTaskAssignmentInstancesReport.List | Not implemented |
| StorageTaskAssignments.Create | Not implemented |
| StorageTaskAssignments.Delete | Not implemented |
| StorageTaskAssignments.Get | Not implemented |
| StorageTaskAssignments.List | Not implemented |
| StorageTaskAssignments.StopAssignment | Not implemented |
| StorageTaskAssignments.Update | Not implemented |
| StorageTaskAssignmentsInstancesReport.List | Not implemented |
