Shared access signatures (SAS) grant time-bound, scoped access to Azure Storage resources without sharing account keys. Over time, Azure Storage has continued to strengthen SAS security, moving from account keys to user delegation (UD) SAS secured by Microsoft Entra ID. Today, we’re taking the next step forward by announcing public preview for user-bound user delegation SAS , an extension of UD SAS that ensures a SAS token can only be used by a specific Entra ID identity.