Restricts a storage account's public endpoint through IP, VNet, resource instance and trusted-service rules. When no rule exists, the endpoint is reachable from any network.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Storage firewall in context, with comparison tables and the common traps.
Terms in this definition
- Storage account
The top-level resource in Azure Storage, giving a unique namespace for table, queue, file and blob data. Location, performance and kind are set when it is created and cannot change.
- Public endpoint
When a service has a public IP, anyone online can attempt a connection, with authentication and firewall rules deciding who gets in. Private endpoints and service endpoints offer private alternatives.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
Related terms
- IP network rule
A storage firewall entry (
IpRules) permitting a public IPv4 address or CIDR range, for example an on-premises egress range. An account can hold up to 400; they cannot match private addresses and do not affect requests from the same Azure region.