By default a storage account's endpoints accept connections from any network, relying only on authorization to keep data safe. The storage firewall (the Networking blade) adds a network layer. Public network access can be Enabled from all networks, Enabled from selected virtual networks and IP addresses, or Disabled. With selected networks, you add virtual network subnets (which need the Microsoft.Storage service endpoint) and public IP ranges in CIDR form; private IP ranges cannot be used in IP rules. With Disabled, only private endpoints can reach the account. Network rules are enforced on all protocols, including REST and SMB, and a request must pass both the firewall and authorization.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.