## TL;DR

Default to private containers and use the blob access level only for content meant to be public. Agents that set container-level access for a single public file expose the full inventory of the container to anyone who asks.

## Steps

1. Default to private containers and use the blob access level only for content meant to be public. Prefer SAS tokens over public access for time-limited sharing. Audit existing containers for container-level public access and tighten them.

## When to use

You are seeing this: Prefer SAS tokens over public access for time-limited sharing. Use this skill when you run into "Azure container-level public access also exposes the blob listing".

## When not to use

If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.

## Versions

No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.

## Why this happens

The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.
