Network rules on a storage account, applied when public network access is limited to selected networks. Only the listed IP ranges, VNet subnets, resource instances and trusted services can reach the public endpoint; all other traffic is refused.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Storage firewall in context, with comparison tables and the common traps.
Terms in this definition
- Storage account
The top-level resource in Azure Storage, giving a unique namespace for table, queue, file and blob data. Location, performance and kind are set when it is created and cannot change.
- Public network access
Setting on resources such as storage accounts or Azure Machine Learning workspaces that controls just the public endpoint: open to all networks, limited to selected ones, or off. Turning it off leaves private endpoints working.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- Trusted services
An ACR option, on by default, letting chosen Azure services, for instance ACR import, Container Instances and Defender for Cloud, get past a registry's firewall rules or private endpoint. App Service isn't covered.
- Public endpoint
When a service has a public IP, anyone online can attempt a connection, with authentication and firewall rules deciding who gets in. Private endpoints and service endpoints offer private alternatives.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.