StudyToCert

All certifications / SC-500 / Lessons

Microsoft Certified: Cloud and AI Security Engineer Associate (replaces Azure Security Engineer Associate / AZ-500) SC-500 · Domain 2: Secure storage, databases, and networking

Storage firewall, trusted services exceptions, and Defender for Storage (activity monitoring, malware scanning, sensitive data threat detection)

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

By default a storage account's endpoints accept connections from any network, relying only on authorization to keep data safe. The storage firewall (the Networking blade) adds a network layer. Public network access can be Enabled from all networks, Enabled from selected virtual networks and IP addresses, or Disabled. With selected networks, you add virtual network subnets (which need the Microsoft.Storage service endpoint) and public IP ranges in CIDR form; private IP ranges cannot be used in IP rules. With Disabled, only private endpoints can reach the account. Network rules are enforced on all protocols, including REST and SMB, and a request must pass both the firewall and authorization.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study plan