Overview of the Azure Storage firewall
The Azure Storage firewall provides basic access control for the public endpoint of your storage accounts and, by default, allows public access. Enabling selected IP addresses or virtual networks allows you to configure the Azure Storage firewall with known IP addresses or IP address ranges based on other cloud-based services or on-premises networks. The following configuration options, as shown in Figure 6.2, depict Public network access, Virtual networks, Firewall, and Exceptions settings:
Figure 6.2 – Overview of firewall and virtual network settings for an Azure Storage account
In addition, you can completely block public network access when using a feature called Private Endpoints (note that enabling Private Endpoints will bypass the Azure Storage firewall). While Private Endpoints may be currently out of scope for the AZ-801 exam, this is a security topic that can’t be missed, so additional recommended...