Soru

Zorluk: ZorConfigure Storage Account Network Access

An administrator is managing an Azure subscription that includes a virtual network named VNet1. VNet1 contains two subnets: Subnet1 and Subnet2. The administrator configures a storage account named storageapp2026 with the firewall set to allow access from 'Selected networks'. Subnet1 has the 'Microsoft.Storage' service endpoint enabled, and the storage account firewall explicitly allows access from Subnet1. Subnet2 contains a private endpoint for the blob service of storageapp2026, which is integrated with a private DNS zone named privatelink.blob.core.windows.net. When the administrator configures Azure Backup to protect the blob containers in storageapp2026, the backup jobs fail with network connectivity errors. Which configuration change should the administrator implement to resolve the backup failure while maintaining the highest level of network security?

  1. Enable the 'Allow trusted Microsoft services to access this storage account' exception on the storage account firewall.Cevap
  2. B
    Configure a Virtual Network link on the private DNS zone to link it to the Azure Backup service virtual network.
  3. C
    Assign the Storage Blob Data Contributor role to the backup vault's managed identity at the storage account level.
  4. D
    Add the public IP addresses of the Azure Backup vault to the firewall IP routing rules of the storage account.

Cevap

Enable the 'Allow trusted Microsoft services to access this storage account' exception on the storage account firewall.
The correct option is to enable the exception that allows trusted Microsoft services to access the storage account. Azure Backup is recognized as a trusted Microsoft service, and enabling this bypass allows the service to connect to the secured storage account and perform backup and restore operations securely.

Adım Adım Çözüm

1
Analyze the error context.
The storage account firewall is configured to block public network traffic except from Subnet1, and Azure Backup (a managed service) is unable to connect to the storage account.
Identify why the connection is blocked at the network level.
2
Evaluate the bypass exceptions.
Azure Backup is classified as a trusted Microsoft service.
Enabling the trusted services bypass allows Azure Backup to securely perform backup tasks without exposing the storage account to the public internet.
3
Apply the configuration change.
Check the checkbox for 'Allow trusted Microsoft services to access this storage account' in the Networking settings of the storage account.
This establishes the necessary secure channel for Azure Backup to access storage resources.

Anahtar Kavram

Azure Storage Firewall Bypass for Trusted Microsoft Services
Bu soruyu puanla