How to get an updated listing for accounts requiring Update host keys to use SFTP on Azure Blob Storage

Justin Tang (NETAPP INC) 20 Reputation points
2026-05-27T16:54:05.82+00:00

Hello, is there an ability to pull a current list of accounts requiring remediation for the email notification sent titled Update host keys to use SFTP on Azure Blob Storage? There is a static list of accounts in the email notification, but no dashboard linked.

Azure Blob Storage
Azure Blob Storage

An Azure service that stores unstructured data in the cloud as blobs.

0 comments No comments

Answer accepted by question author
Jerald Felix 18,760 Reputation points Volunteer Moderator
2026-05-29T04:52:11.2666667+00:00

Hello Justin Tang (NETAPP INC)

Greetings! Thanks for raising this question in Q&A forum.

That's a great and practical question! The reason there's no live dashboard linked in the email notification is that Microsoft currently does not provide a built-in dynamic view or portal page to track which storage accounts still require remediation for SFTP host key updates. The email only includes a static snapshot of affected accounts at the time it was sent. However, there are a few ways you can identify and track this yourself across your environment.

Here's what you can do step by step:

Step 1: Use Azure Resource Graph to Query Storage Accounts with SFTP Enabled

The quickest way to get an up-to-date list is to run a query using Azure Resource Graph Explorer. Go to the Azure Portal, search for Resource Graph Explorer, and run a query to find all storage accounts that have SFTP enabled. This gives you a live, current list across all your subscriptions. Here's a simple query you can use:

resources
| where type == "microsoft.storage/storageaccounts"
| where properties.isSftpEnabled == true
| project name, resourceGroup, subscriptionId, location

Step 2: Cross-Check Against the Static List in the Email

Take the accounts listed in the Microsoft notification email and compare them against the results from your Resource Graph query. Any account that still appears in both lists has not yet been remediated.

Step 3: Verify and Update Host Keys on Each Affected Account

For each storage account that needs remediation, go to the Azure Portal, open the storage account, navigate to SFTP under Settings, and regenerate or verify the host keys to ensure they are updated to the current valid keys. You can also refer to the valid host keys per region here: https://learn.microsoft.com/azure/storage/blobs/secure-file-transfer-protocol-host-keys

Step 4: Use Azure Policy or Azure Advisor for Ongoing Monitoring

To avoid missing similar notifications in the future, consider setting up an Azure Policy to audit storage accounts with SFTP enabled and flag those that don't meet your configuration standards. You can also check Azure Advisor in the portal regularly, as it sometimes surfaces remediation recommendations for managed services.

Step 5: Set Up Azure Service Health Alerts

Go to Azure Service Health → Health Alerts in the portal and create an alert rule for your subscriptions. This way, whenever Microsoft sends out a similar action required notification in the future, you'll be notified automatically and can act right away without relying on a manual email.

If you manage a large number of subscriptions, you can also script the Resource Graph query using Azure CLI or PowerShell to automate the discovery and reporting process across your entire tenant.

If this answer helps you kindly accept the answer which will help others who have similar questions.

Best Regards,

Jerald Felix.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

2 additional answers

Sort by: Most helpful
  1. kagiyama yutaka 5,570 Reputation points
    2026-05-29T13:20:45.5233333+00:00

    I think Azure only lets u list the Storage Accounts with SFTP enabled, and there is no way to pull a live list of the ones needing the host‑key update, so u just check each SFTP page for the notice.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-05-27T16:54:17.4766667+00:00

    The available documentation for SFTP host keys on Azure Blob Storage describes what host keys are, how to verify them, and lists the valid keys per region, but does not provide any mechanism, API, or portal view to retrieve a dynamic or updated list of storage accounts that require remediation based on the “Update host keys to use SFTP on Azure Blob Storage” notification.

    No dashboard, query, or listing mechanism for affected accounts is documented in the provided material.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.