You lock down a storage account to Selected networks. Requirements: (1) Allow access from your on-premises public IP ranges, (2) allow an Azure VM in a specific subnet to access the account, and (3) permit Azure Data Factory (a trusted Microsoft service) to continue operating. Which configuration meets all requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Add the on-premises public IP ranges to IP network rules, Add the VM’s subnet to virtual network rules and enable the Microsoft.Storage service endpoint on that subnet, Enable the exception Allow Azure services on the trusted services list for this storage account.
Why this is the answer
To meet requirement (1), adding the on-premises public IP ranges to IP network rules directly allows traffic from those specific IPs. For requirement (2), adding the VM's subnet to virtual network rules and enabling the Microsoft.Storage service endpoint on that subnet ensures that traffic from the VM's private IP within that subnet can securely access the storage account over the Azure backbone, bypassing the public internet. For requirement (3), enabling the exception "Allow Azure services on the trusted services list for this storage account" permits trusted Microsoft services like Azure Data Factory to access the storage account even when network rules are in place. Granting the Storage Blob Data Contributor role to the Data Factory managed identity is for authorization, not network access control, so it doesn't bypass firewall rules. Adding the outbound public IPs of the VM to IP network rules is incorrect because service endpoints provide a more secure and direct path for Azure resources within a VNet.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed