Storage account network connectivity issues

Nana Poku 185 Reputation points
2025-02-28T16:40:59.8666667+00:00

We have issues with logic apps being unable to access storage accounts within Azure, when doing error check, there are some errors around the blob and file services. Deleting the private endpoint and recreating them resolved the issue.

Upon further checks I realised we had public access in our storage account enabled and private endpoint also enabled, would this be the cause of the connectivity error ?

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,394 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Keshavulu Dasari 3,790 Reputation points Microsoft External Staff
    2025-02-28T16:58:37.4033333+00:00

    Hi Nana Poku ,

    your understanding is correct Yes having both public access and a private endpoint enabled on your Azure storage account can indeed cause connectivity issues. When a private endpoint is configured, it creates a private IP address within your virtual network, and the storage account should ideally be accessed through this private endpoint. If public access is also enabled, it can lead to conflicts and connectivity problems because the traffic might not be routed correctly. I suggest few key points to consider,

    When a private endpoint is created, a private DNS zone is typically configured to resolve the storage account's FQDN to the private IP address. If public access is enabled, DNS resolution might still point to the public endpoint, causing connectivity issues

    Ensure that your storage account's firewall and virtual network rules are configured to allow access only through the private endpoint. Public access should be disabled to avoid conflicts

    If you have service endpoints configured, they might interfere with the private endpoint. It's generally recommended to use either service endpoints or private endpoints, but not both simultaneously

    Please disable public access on your storage account and ensure that all traffic is routed through the private endpoint. This will help maintain a consistent and secure connection to your storage account.

    For more information:
    https://learn.microsoft.com/en-us/azure/private-link/tutorial-private-endpoint-storage-portal?tabs=dynamic-ip


    Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members. 

    User's image

    If you have any other questions or are still running into more issues, let me know in the "comments" and I would be happy to help you.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.