Hello Uri Zafrir,
Welcome to Microsoft Q&A, thanks for posting your query.
Adding to the above answer when public network Access is enabled, it allows access to the storage account from any network, including the public internet and creates a private connection between your virtual network and the Azure Files service, allowing secure access without exposing the file share to the public internet.
I understand that You've enabled Public Network Access, which allows access from anywhere and also created a Private Endpoint, which is designed for secure, private access. This creates a conflict. While you can access the file share from within your virtual network (due to the private endpoint), external access might be blocked or inconsistent due to the conflicting access control settings.
- Go to your storage account.
- Navigate to Settings -> Configuration.
- Under Blob service or File service, set "Allow blob public access" or "Allow file public access" to Disabled.
- After disabling public access, ensure that you can still access the file share from within your virtual network.
Disabling public access is crucial for enhancing the security of your Azure Files share. Thoroughly test your file share access after disabling public network access to ensure that all expected functionalities work as intended. By disabling public network access, you'll align your storage account's access control with the security benefits provided by the Private Endpoint.
If you're still encountering issues after these steps, please provide more details about:
How are you trying to access the file share from outside the virtual network (e.g., directly from the internet, from another Azure resource)?
Any specific error messages you are encountering?
Please let us know if you have any further queries. I’m happy to assist you further.
If this answers your query, do click "Accept the answer” for the same, which might be beneficial to other community members reading this thread. And, if you have any further queries do let us know.