# Azure Blob Storage Setup & Tier Management

> How to connect Blober to Azure Blob Storage. Browse containers, transfer blobs, and change access tiers (Hot, Cool, Cold, Archive) in bulk.

Azure Blob Storage is Microsoft's scalable object storage solution for the cloud, ideal for storing large amounts of unstructured data. In Blober, Azure paths use:

```plaintext
container-name/path/to/blob.ext
```

## Capabilities

* ✅ Browse containers and blobs
* ✅ Upload files
* ✅ Download files
* ✅ Delete files
* ✅ Change blob tier (Hot/Cool/Cold/Archive)
* ✅ Change container access level (Private/Blob/Container)
* ✅ View blob metadata

## Prerequisites

* An Azure account ([create one free](https://azure.microsoft.com/free/))
* An Azure Storage account
* Storage account access keys or connection string

## Required credentials

[]()

### Connection string

* **Format:** A connection string containing account name, key, and endpoint

Example:

```plaintext
DefaultEndpointsProtocol=https;AccountName=myaccount;AccountKey=mykey;EndpointSuffix=core.windows.net
```

## Optional settings

[]()

### Storage tier

* **Default:** `Cool`
* **Used for:** Destination
* **Values:** `Hot`, `Cool`, `Cold`, `Archive`

Sets the access tier for newly uploaded blobs.

**Access tier guidance:**

| Tier    | Use Case                         | Retrieval Cost |
| ------- | -------------------------------- | -------------- |
| Hot     | Frequently accessed data         | Lowest         |
| Cool    | Infrequently accessed (30+ days) | Low            |
| Cold    | Rarely accessed (90+ days)       | Medium         |
| Archive | Long-term backup (180+ days)     | Highest        |

[]()[]()

### Deduplication

* **Default:** Skip if a file with the same name exists
* **Used for:** Destination

For the policies (skip, overwrite), where the control appears, and how deduplication differs from resuming a task, see [Deduplication](/kb/docs/getting-started/deduplication/).

> **Caution**
>
> Azure-specific: archived blobs are always skipped, whichever value is selected. An archived blob cannot be rewritten, so Blober records it as skipped instead of failing the transfer. Rehydrate the blob first if you want to replace it.

## Mutation options

These options appear when using Azure Blob Storage as a **mutate** action in a workflow. Only one mutation can be active at a time.

[]()

### Change storage tier

* **Default:** `Cool`
* **Required:** Yes (when selected)
* **Values:** `Hot`, `Cool`, `Cold`, `Archive`

Move selected blobs to a different storage tier. Use this to change the access tier of existing blobs, for example, moving infrequently accessed data from Hot to Cool or Archive.

> **Caution**
>
> Rehydrating blobs from **Archive** tier can take several hours and incurs an early deletion fee if the blob was archived less than 180 days ago.

[]()

### Container access level

* **Default:** `private`
* **Required:** Yes (when selected)

Change the public access level of selected containers.

| Value       | Behavior                                                    |
| ----------- | ----------------------------------------------------------- |
| `private`   | No public access. All requests must be authenticated        |
| `blob`      | Anonymous read access for blobs only                        |
| `container` | Anonymous read access for both container metadata and blobs |

> **Caution**
>
> Setting a container to **blob** or **container** access level makes its contents publicly readable on the internet. Only use this for data you intend to share publicly.

## Setup (Azure Portal)

### 1. Create a Storage Account

1. Go to [Azure Portal](https://portal.azure.com)

2. Search for "Storage accounts"

3. Click **"Create"**

4. Fill in:

   * **Subscription:** Your Azure subscription
   * **Resource group:** Create new or use existing
   * **Storage account name:** Unique name (e.g., `mybloberstorage`)
   * **Region:** Choose closest to you
   * **Performance:** Standard (or Premium for high-performance needs)
   * **Redundancy:** LRS (locally redundant) for cost savings

5. Click **"Review + create"** => **"Create"**

### 2. Get Connection String

1. Open your Storage account in Azure Portal
2. In the left menu, go to **Security + networking** => **Access keys**
3. Click **"Show"** next to key1
4. Copy the **Connection string** (not just the key)

### 3. Configure in Blober

1. In Blober, go to **Workflows** => **New Workflow**
2. Select **Azure Blob Storage** as source or destination
3. Paste the connection string
4. Test the connection by browsing

## Troubleshooting

### "Invalid connection string"

* Make sure you copied the **full** connection string, including `DefaultEndpointsProtocol=https;...`
* Don't copy the key alone - you need the entire connection string

### "Container not found"

* Check the container name is correct (case-sensitive)
* Ensure the container exists in your storage account

### Slow uploads to Archive tier

* Archive tier has higher write latency - this is normal
* Consider uploading to **Cool** first, then using Azure Lifecycle Management to transition to Archive

## Notes

* Move infrequently accessed data to **Cool** or **Archive** tiers

## Best Practices

### Cost Management

* Use **Cool** tier for data accessed less than once a month - significant savings over Hot
* Use **Archive** tier for long-term backups you rarely need - lowest storage cost
* Set up [Lifecycle Management rules](https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-overview) to automatically transition blobs between tiers
* Monitor costs with [Azure Cost Management](https://portal.azure.com/#blade/Microsoft_Azure_CostManagement)

### Security

* Use **SAS tokens** with limited permissions and expiry instead of full account keys when possible
* Rotate access keys periodically
* Enable **soft delete** for blob recovery in case of accidental deletion
* Keep your connection string secure and never share it publicly

### Performance

* Upload to **Cool** tier first, then use lifecycle rules to move to Archive - avoids high Archive write latency
* Choose a storage account region close to your location for best transfer speeds
* Use **LRS** (Locally Redundant Storage) for cost savings when geo-redundancy isn't required

> **Terms Compliance**
>
> Your use of Azure Blob Storage through Blober is subject to [Microsoft's Service Agreement](https://www.microsoft.com/en-us/servicesagreement). See our [Terms of Service](/kb/docs/terms-and-privacy/terms-of-service/) for details.

## External References

* [Azure Storage Connection Strings](https://learn.microsoft.com/en-us/azure/storage/common/storage-configure-connection-string)
* [Access Tiers Overview](https://learn.microsoft.com/en-us/azure/storage/blobs/access-tiers-overview)
* [Azure Blob Storage Documentation](https://docs.microsoft.com/en-us/azure/storage/blobs/)
* [Security Best Practices](https://learn.microsoft.com/en-us/azure/storage/blobs/security-recommendations)
* [Set up Lifecycle management rules](https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-overview)
* [Azure Cost Management](https://portal.azure.com/#blade/Microsoft_Azure_CostManagement)