If we enable the private endpoints for storage account, can't we able to access storage account by using VNETs

Kumar, Addala (623) 0 Reputation points
2023-12-22T09:22:17.1233333+00:00

I have a storage account (stgA) with its networking set to "Enabled from selected virtual networks and IP addresses." I've successfully added VNETA to access stgA, and I can access the storage from the VNET. However, after creating a private endpoint for this storage account, I'm no longer able to access it from the VNET. Is there any method to access the storage account other than using private endpoints when the private endpoint is enabled?

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,532 questions
Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
518 questions
{count} votes

1 answer

Sort by: Most helpful
  1. KapilAnanth-MSFT 47,206 Reputation points Microsoft Employee
    2023-12-27T16:36:40.6233333+00:00

    @Kumar, Addala (623)

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you are unable to connect to storage account after enabling Private EndPoint.

    Please note :

    • Creating a Private EndPoint will not block Public access by default.
    • It will only create a NIC in the target VM so that you can access it Privately in addition to being able to access Publicly.

    With the above said, I asked

    • From your screenshot, is your DNS Server 168.63.129.16
    • Can you share the results of nslookup <YOURRESOURCE>.dfs.core.windows.net 8.8.8.8
      • This was working fine - we were able to get the Public IP resolved.
    • Do you have a "privatelink.dfs.core.windows.net" already linked to this VNET?
      • You confirmed yes

    So I suggested we remove the "privatelink.dfs.core.windows.net" link to this VNET.

    You informed this resolved the issue.

    Cheers,

    Kapil


    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.