By default a new storage account accepts connections from any network and relies on authorization (keys, shared access signatures or Microsoft Entra ID) to keep data safe. The storage firewall adds a network layer: even a request with a valid key is refused if it does not come from an allowed network. You configure it under the account's Networking blade, where public network access can be enabled from all networks, enabled from selected virtual networks and IP addresses, or disabled. Defense in depth means using both layers: strong authorization and restricted networks.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.