Tag: Azure Storage

Configure Azure Storage firewall rules (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure storage, databases, and networking (25–30%)
   --> Implement security for storage accounts
      --> Configure Azure Storage firewall rules


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Azure Storage firewall rules provide network-layer controls that restrict access to a storage account through its public endpoint. They allow you to specify which networks, public IP addresses, Azure resource instances, or trusted Azure services can connect to the account.

By default, an Azure Storage account is reachable from any network. Configuring firewall rules reduces the storage account’s network attack surface by allowing access only from approved sources. However, firewall rules control network reachability, not data authorization. A client must satisfy both the network rules and the storage account’s authentication and authorization requirements.


What Azure Storage Firewall Rules Control

Azure Storage firewall rules control access to the storage account’s public endpoint.

They can allow traffic from:

  1. Specific Azure virtual network subnets
  2. Specific public IP address ranges
  3. Specific Azure resource instances
  4. Selected trusted Azure services

All other traffic is denied when the firewall’s default action is set to Deny.

Firewall rules apply to data-plane access, such as reading or writing blobs, files, queues, or tables. They do not replace Azure Resource Manager permissions used for management-plane operations.

Important distinction

A request must pass two separate security checks:

Security layerMain question
Network securityIs this source allowed to reach the storage endpoint?
Data authorizationDoes this identity or credential have permission to access the data?

For example, a virtual machine might be allowed through the storage firewall but still receive an authorization error if its managed identity does not have the required Storage Blob Data role.


Storage Network Access Options

Azure Storage supports several network access models.

1. Public network access

Public network access allows clients to connect to the storage account’s public endpoint.

You can configure public access in two general ways:

  • Allow access from all networks
  • Allow access from selected networks

The second option enables firewall rules and allows you to restrict access to approved sources.

For most production workloads, unrestricted public network access should be avoided unless there is a clear business requirement.


2. Private endpoints

A private endpoint assigns a private IP address from an Azure virtual network to the storage account. Clients connect to the storage account through Azure Private Link, and traffic travels over the Microsoft backbone rather than the public internet.

For maximum isolation, configure a private endpoint and disable public network access. This causes the storage account to accept traffic only through private connectivity.

Important exam distinction

Creating a private endpoint does not automatically disable the public endpoint.

You must separately configure the storage account’s public network access setting if you want to eliminate public endpoint exposure.

Private endpoints and firewall rules

Storage firewall rules apply to the public endpoint. They do not control traffic arriving through a private endpoint.

Therefore:

  • Public endpoint traffic is evaluated by public network rules.
  • Private endpoint traffic uses private connectivity.
  • Disabling public network access is the strongest way to ensure that the public endpoint cannot be used.

3. Network security perimeter

A network security perimeter can provide a broader security boundary around supported Azure resources, including storage accounts.

Unlike an individual storage firewall, a network security perimeter can define inbound and outbound access rules for a group of resources. It can also help control data exfiltration.

When a storage account is associated with a perimeter in Enforced mode, perimeter rules take precedence over the storage account’s own firewall settings for applicable public traffic. Private endpoint traffic is not subject to the perimeter rules.

For the SC-500 exam, remember:

  • Storage firewall rules are configured at the storage-account level.
  • Network security perimeters can establish a broader boundary around multiple resources.
  • Private endpoint traffic is treated separately from public network traffic.

The Four Types of Storage Network Rules

1. Virtual network rules

Virtual network rules allow traffic from specified subnets in Azure virtual networks.

To use a virtual network rule with a public storage endpoint, the subnet must have an Azure Storage service endpoint enabled.

Supported service endpoints include:

  • Microsoft.Storage
  • Microsoft.Storage.Global

The service endpoint allows traffic from the subnet to reach Azure Storage using Azure networking rather than appearing as traffic from the subnet’s public IP address.

Configuration process

A typical configuration involves:

  1. Open the storage account.
  2. Select Networking.
  3. Set public network access to selected networks.
  4. Set the default network action to Deny.
  5. Add the required virtual network and subnet.
  6. Enable the appropriate Storage service endpoint on the subnet.
  7. Save the network configuration.
  8. Verify that the application can access the storage account.

The Azure portal can automatically configure the service endpoint when you select a subnet. When using PowerShell, Azure CLI, or infrastructure as code, you may need to configure the service endpoint separately.

Example scenario

An application runs on virtual machines in:

  • Virtual network: AppVNet
  • Subnet: ApplicationSubnet

You want only those virtual machines to access the storage account’s public endpoint.

The appropriate solution is to:

  • Enable a Storage service endpoint on ApplicationSubnet
  • Add ApplicationSubnet to the storage account’s virtual network rules
  • Set the storage firewall’s default action to Deny

Important limitation

If a subnet uses a Storage service endpoint, its traffic does not appear to originate from the subnet’s public IP address. Consequently, an IP rule for that subnet’s public IP address does not provide the expected access.


2. IP network rules

IP network rules allow traffic from specified public IPv4 address ranges.

They are useful when access must be granted to:

  • Corporate office networks
  • On-premises environments
  • Internet-facing application servers
  • Approved administrative workstations
  • Specific public NAT gateways

Examples of valid IP rules

You can specify:

  • An individual public IPv4 address
  • A public IPv4 range in CIDR notation

Examples:

20.30.40.50
20.30.40.0/24

On-premises access

For on-premises clients, identify the public IP addresses that the network uses when connecting to Azure.

If the organization uses ExpressRoute, determine the appropriate NAT IP addresses used for Microsoft peering. The addresses configured in the firewall must represent the public addresses visible to Azure Storage.

IP rule limitations

Azure Storage IP firewall rules have several important restrictions:

  • Only public IPv4 addresses are supported.
  • Private RFC 1918 addresses cannot be used.
  • Private ranges such as 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 are not valid public IP firewall rules.
  • Small ranges using /31 or /32 are not supported as CIDR ranges; use an individual IP address rule instead.
  • IP rules do not restrict clients in the same Azure region as the storage account.
  • IP rules do not restrict Azure services in the same region that communicate using private Azure IP addresses.

Important exam trap

If an application runs in Azure and the storage account is in the same region, adding the application’s public outbound IP address to the storage firewall may not work as expected.

Use a virtual network rule and Storage service endpoint, or use a private endpoint instead.


3. Azure resource instance rules

Resource instance rules allow specific Azure resource instances to access the storage account’s public endpoint.

This is useful when the Azure resource cannot be conveniently isolated by:

  • A virtual network rule
  • An IP address rule

Examples may include selected Azure platform or PaaS resources.

A resource instance rule identifies a specific resource instance, such as a particular Azure service resource. The resource’s identity and role assignments determine what it can do with storage data.

Important distinction

A resource instance rule allows the resource to pass the network boundary. It does not automatically grant access to the data.

The resource must also have an appropriate data-plane role assignment, often through its system-assigned managed identity.

For example:

  • A Data Factory instance is allowed by a resource instance rule.
  • Its managed identity is assigned Storage Blob Data Reader.
  • The Data Factory instance can then read permitted blob data.

Without the data role assignment, the resource may pass the firewall but still be denied access to the data.

Resource instance requirements

Resource instances must be from the same Microsoft Entra tenant as the storage account, although they can belong to different subscriptions within that tenant.


4. Trusted Azure service exceptions

Some Azure services operate outside the virtual network or public IP boundaries that you configure.

A trusted service exception allows selected Azure services to access the storage account even though their traffic does not match a virtual network or IP rule.

This can be useful for services that need to:

  • Read resource logs
  • Read metrics
  • Perform supported backup or monitoring operations
  • Access storage from Azure-managed infrastructure

Trusted service exceptions use strong authentication, but they should still be enabled carefully because they create a broader exception than a rule for one specific resource instance.

Trusted service exception versus resource instance rule

FeatureResource instance ruleTrusted service exception
ScopeSpecific resource instanceSupported Azure service category
GranularityMore specificBroader
Typical useAllow one Data Factory or other resourceAllow a supported Azure service operating outside your network
Identity requirementsResource identity and appropriate roleService-supported strong authentication
Security preferencePrefer when practicalUse only when necessary

Exam guidance

If the requirement says:

Allow one specific Azure resource to access the storage account.

Prefer a resource instance rule.

If the requirement says:

Allow a supported Azure service to access the account from outside the configured network boundary.

A trusted service exception may be appropriate.


The Default Network Action

The storage firewall has a default network action:

  • Allow
  • Deny

Default action: Allow

When the default action is Allow, traffic from sources that are not explicitly listed can still access the public endpoint.

Adding individual rules while leaving the default action as Allow does not create a restrictive firewall.

Default action: Deny

When the default action is Deny, only explicitly allowed sources can access the public endpoint.

This is the standard configuration for a restricted storage account.

Recommended sequence

To reduce the risk of accidentally interrupting application access:

  1. Identify all required clients and services.
  2. Configure private endpoints, virtual network rules, IP rules, resource instance rules, or trusted service exceptions.
  3. Verify authentication and authorization.
  4. Change the default action to Deny.
  5. Test all required workloads.
  6. Monitor denied requests and update rules as necessary.

Network rules have no restrictive effect unless the default action is set to Deny.


Storage Firewall Configuration in the Azure Portal

A typical portal configuration is:

  1. Open the Azure portal.
  2. Navigate to the storage account.
  3. Select Networking under Security + networking.
  4. Under Public network access, select the appropriate option.
  5. Choose Enabled from selected virtual networks and IP addresses when using firewall rules.
  6. Under Virtual networks, add approved virtual networks and subnets.
  7. Under Firewall, add approved public IPv4 addresses or ranges.
  8. Under Resource instances, add approved Azure resource instances if required.
  9. Under Exceptions, configure only the necessary trusted service exceptions.
  10. Set the default network action to Deny.
  11. Save the configuration.
  12. Test access from both an approved and an unapproved source.

The exact portal labels can change over time, but the underlying concepts remain:

  • Define allowed sources.
  • Set the default action to Deny.
  • Confirm that the client also has data authorization.

Azure CLI Examples

Set the default action to Deny

az storage account update \
--resource-group MyResourceGroup \
--name mystorageaccount \
--default-action Deny

Add an IP network rule

az storage account network-rule add \
--resource-group MyResourceGroup \
--account-name mystorageaccount \
--ip-address 20.30.40.50

Add a virtual network rule

az storage account network-rule add \
--resource-group MyResourceGroup \
--account-name mystorageaccount \
--vnet-name AppVNet \
--subnet ApplicationSubnet

The subnet must have the appropriate Storage service endpoint configured.

View network rules

az storage account network-rule list \
--resource-group MyResourceGroup \
--account-name mystorageaccount

Commands and parameters can vary by Azure CLI version and storage resource configuration. Always verify the currently supported command syntax before using it in production automation.


Firewall Rules and Authentication

Firewall rules do not replace authentication.

A client that is allowed by the firewall must still authenticate using an accepted method, such as:

  • Microsoft Entra ID
  • Managed identity
  • Shared Key
  • SAS token
  • Another supported authorization mechanism

For example, a virtual machine can be allowed through the firewall but still fail because its managed identity lacks:

  • Storage Blob Data Reader
  • Storage Blob Data Contributor
  • Storage Blob Data Owner

The reverse is also true: an identity may have a valid data role but still be blocked by the network firewall.

Security principle

Use both:

  • Network restrictions to limit where requests can originate
  • Least-privilege authorization to limit what the caller can do

Firewall Rules and SAS Tokens

A SAS token can restrict access to a specific IP address, but the SAS token does not override the storage firewall.

A SAS token:

  • Grants the permissions encoded in the token
  • May restrict access by IP
  • May restrict protocol, time, resource, and operation
  • Does not create network access when the storage firewall denies the source

Therefore, if a client is outside the allowed firewall boundary, a valid SAS token alone is insufficient.

Exam trap

A question may state that a user has a valid SAS token but receives a network-related error. The correct solution may be to update the firewall rule rather than create a new SAS token.


Firewall Rules and Private Endpoints

Private endpoints are generally preferred when:

  • Workloads are entirely within Azure
  • Clients can connect through a virtual network
  • Public exposure must be eliminated
  • The organization requires private connectivity
  • Data exfiltration risk must be minimized

A common secure design is:

  1. Create a private endpoint for the storage account.
  2. Configure private DNS resolution.
  3. Verify that clients resolve the storage account name to the private endpoint IP address.
  4. Disable public network access.
  5. Use Microsoft Entra ID and managed identities for authorization.

Common mistake

Creating a private endpoint but leaving public network access enabled does not eliminate the public attack surface.


Common Configuration Mistakes

Mistake 1: Leaving the default action as Allow

Adding a few IP or virtual network rules does not restrict all other sources if the default action remains Allow.

Correction: Set the default action to Deny.

Mistake 2: Using private IP addresses in IP firewall rules

Private RFC 1918 addresses cannot be used as public IP firewall rules.

Correction: Use a virtual network rule, service endpoint, or private endpoint.

Mistake 3: Using IP rules for same-region Azure workloads

Same-region Azure traffic may use private Azure IP addresses and therefore may not be restricted by public IP rules.

Correction: Use a virtual network rule with a service endpoint or use a private endpoint.

Mistake 4: Assuming firewall access grants data access

Network access and data authorization are separate.

Correction: Assign the appropriate data-plane role or use another supported authorization method.

Mistake 5: Assuming a private endpoint disables public access

It does not.

Correction: Explicitly disable public network access when public exposure must be removed.

Mistake 6: Enabling broad trusted service exceptions unnecessarily

Trusted service exceptions can be broader than required.

Correction: Prefer a resource instance rule or private connectivity when the requirement permits.

Mistake 7: Forgetting ExpressRoute NAT addresses

The firewall must allow the public NAT addresses visible to Azure Storage, not arbitrary internal corporate addresses.

Correction: Obtain the correct Microsoft peering NAT addresses from the network team.

Mistake 8: Forgetting the Storage service endpoint

A virtual network rule may not work unless the required service endpoint is enabled on the subnet.

Correction: Enable the appropriate Storage service endpoint and then add the subnet to the storage firewall.


Recommended Security Design

For a highly restricted storage account:

  1. Use a private endpoint.
  2. Disable public network access.
  3. Use private DNS so clients resolve the storage account through the private endpoint.
  4. Use managed identities and Microsoft Entra ID.
  5. Assign only the required Storage data roles.
  6. Disable Shared Key authorization when all dependent applications have migrated.
  7. Use firewall rules only when public endpoint access is necessary.
  8. Set the firewall default action to Deny.
  9. Avoid broad trusted service exceptions.
  10. Monitor diagnostic logs and denied access attempts.
  11. Use Azure Policy to enforce required network configurations.
  12. Test both approved and unapproved access paths.

Exam Summary

Remember these key points:

  • Storage firewall rules apply to the public endpoint.
  • The default action must be Deny for restrictive rules to take effect.
  • Virtual network rules generally require a Storage service endpoint.
  • IP rules use public IPv4 addresses.
  • Private IP addresses cannot be used as public IP firewall rules.
  • IP rules do not reliably restrict same-region Azure traffic.
  • Resource instance rules allow specific Azure resources through the network boundary.
  • Resource instance rules do not automatically grant data access.
  • Trusted service exceptions are broader and should be used carefully.
  • Private endpoints provide private connectivity but do not automatically disable public access.
  • Firewall access and data authorization are separate.
  • SAS tokens do not bypass network restrictions.
  • Private endpoints are not governed by public endpoint firewall rules.

Practice Exam Questions

Question 1

A storage account contains sensitive financial documents. All applications that access the account run in an Azure virtual network. The security team requires that the storage account have no public network exposure.

What should you configure?

A. Add the application subnet’s public IP address to the storage firewall
B. Create a private endpoint and disable public network access
C. Enable the trusted Azure services exception
D. Create a SAS token restricted to the application subnet

Correct Answer: B

Explanation

A private endpoint provides private connectivity from the virtual network to the storage account. Disabling public network access ensures that the public endpoint cannot be used.

The other options do not eliminate public exposure:

  • A relies on public IP filtering.
  • C allows selected Azure services but does not remove public access.
  • D controls authorization and possibly token scope, not public endpoint exposure.

Question 2

An organization wants to allow access to a storage account only from a corporate office. The office connects to Azure over the internet through a known public NAT address.

Which rule should be configured?

A. A virtual network rule using the office’s private IP range
B. A resource instance rule for the office router
C. A trusted service exception
D. An IP network rule for the office’s public NAT address

Correct Answer: D

Explanation

IP network rules are appropriate when access originates from a known public IPv4 address or range.

Private corporate addresses cannot be used in public IP firewall rules. A virtual network rule is intended for Azure virtual network subnets, not arbitrary on-premises private address ranges.


Question 3

A storage account has an IP rule allowing 20.30.40.50, but a virtual machine in the same Azure region cannot access the account. The VM’s outbound traffic is not appearing from that public IP address.

What is the best solution?

A. Add the VM’s private IP address as an IP rule
B. Add a virtual network rule for the VM’s subnet and enable a Storage service endpoint
C. Enable anonymous blob access
D. Create a trusted service exception for the virtual machine

Correct Answer: B

Explanation

Public IP rules do not restrict same-region Azure traffic in the expected way because the traffic may use private Azure IP addresses.

A virtual network rule combined with a Storage service endpoint is the appropriate solution. Private IP addresses cannot be added as public IP firewall rules.


Question 4

A Data Factory instance must access blobs in a storage account. The Data Factory resource cannot be isolated using a virtual network rule, and the security team wants to allow only that specific Data Factory instance.

What should you configure?

A. A resource instance network rule and the required data-plane role assignment
B. A trusted service exception for all Azure services
C. An IP rule for the Data Factory public IP address
D. A SAS token without any firewall rule

Correct Answer: A

Explanation

A resource instance rule allows a specific Azure resource instance to pass the storage account’s network boundary. The resource must also have the appropriate data-plane role, such as Storage Blob Data Reader or Storage Blob Data Contributor.

The network rule alone does not grant access to the data.


Question 5

An administrator adds three IP addresses to a storage account’s firewall but leaves the default network action set to Allow.

What is the result?

A. Only the three IP addresses can access the account
B. All traffic is denied until a private endpoint is created
C. Other sources may still access the public endpoint
D. Only Azure services can access the account

Correct Answer: C

Explanation

The default action determines what happens to traffic that does not match an explicit rule.

When the default action is Allow, sources not listed in the firewall rules may still access the public endpoint. To restrict access to explicitly allowed sources, set the default action to Deny.


Question 6

A company uses ExpressRoute to connect its on-premises network to Azure. The security team wants to permit access to a storage account from the company’s on-premises network.

Which addresses should be added to the storage firewall?

A. The private IP addresses assigned to on-premises computers
B. The ExpressRoute Microsoft peering NAT public IP addresses
C. The Azure virtual network address space
D. The storage account’s private endpoint IP address

Correct Answer: B

Explanation

For on-premises access through ExpressRoute, the storage firewall must allow the public NAT IP addresses used for Microsoft peering.

Internal private IP addresses are not valid public IP firewall rules. The Azure virtual network address space is also not the correct representation of the source for this scenario.


Question 7

A storage account firewall allows traffic from an approved subnet. A workload in that subnet receives a 403 error when attempting to read blobs. Network connectivity tests show that the request reaches the storage account.

What is the most likely missing configuration?

A. A second IP firewall rule
B. A private endpoint
C. A trusted service exception
D. A data-plane authorization assignment

Correct Answer: D

Explanation

The firewall allows the workload to reach the storage account, but network access does not grant data access.

The workload’s identity must have an appropriate data-plane role, such as:

  • Storage Blob Data Reader
  • Storage Blob Data Contributor
  • Storage Blob Data Owner

A 403 response after network access succeeds commonly indicates an authorization issue.


Question 8

A developer creates a private endpoint for a storage account. A security audit still detects that the storage account’s public endpoint is reachable from the internet.

What should the developer do?

A. Add the private endpoint IP address as an IP firewall rule
B. Disable public network access on the storage account
C. Enable the trusted Azure services exception
D. Create a SAS token restricted to the private endpoint IP

Correct Answer: B

Explanation

A private endpoint does not automatically disable the public endpoint. To eliminate public exposure, disable public network access after verifying that required clients can use the private endpoint.

The other options do not disable the public endpoint.


Question 9

A storage account must be accessed by a supported Azure service operating outside the organization’s virtual network. The service cannot be represented by a specific virtual network or public IP rule.

Which option may satisfy the requirement?

A. A trusted Azure service exception
B. A private IP firewall rule
C. An anonymous access policy
D. A subnet service endpoint without a network rule

Correct Answer: A

Explanation

Trusted Azure service exceptions are designed for supported Azure services that operate outside the network boundary defined by virtual network and IP rules.

The exception should be enabled only when necessary because it may be broader than a rule for one specific resource instance.


Question 10

A security engineer wants to restrict a storage account to a small set of approved public IPv4 addresses. One address is written as 20.30.40.50/32.

What is the correct approach?

A. Replace it with the private address range 10.0.0.0/8
B. Use an individual IP address rule rather than a /32 CIDR range
C. Convert it to an IPv6 address
D. Add it as a virtual network rule without a service endpoint

Correct Answer: B

Explanation

Azure Storage IP firewall rules support individual public IPv4 addresses. Small ranges using /31 or /32 prefix sizes are not supported as CIDR ranges, so the address should be entered as an individual IP rule.

Private RFC 1918 ranges are not valid public IP firewall rules, and a virtual network rule requires an appropriate subnet configuration.


Final Review Checklist

Before considering a storage firewall configuration complete, verify:

  • Is public network access required?
  • If not, can a private endpoint be used?
  • If a private endpoint is used, has public network access been disabled?
  • Is the firewall default action set to Deny?
  • Are the correct public NAT addresses being used?
  • Are virtual network service endpoints enabled where required?
  • Are resource instance rules limited to the necessary resources?
  • Are trusted service exceptions minimized?
  • Does the calling identity have the required data-plane role?
  • Have approved and unapproved access paths been tested?
  • Are logging, monitoring, and policy enforcement configured?

Go to the SC-500 Exam Prep Hub main page