Ein Azure-Dienst, der unstrukturierte Daten als Blobs in der Cloud speichert.
Hi Kai,
Thanks for reaching out in Microsoft Q&A forum,
Is it possible to restrict access to a Storage Account to a VNet in a different subscription using Service Endpoints?
Yes, Azure Storage Accounts fully support restricting access to VNets located in different subscriptions, provided:
- Both subscriptions are in the same Azure AD tenant
- You have Network Contributor (or higher) permissions on the remote VNet
- The Microsoft.Storage service endpoint is enabled on the source subnet
This is a supported, documented capability though the Azure Portal UI makes it less obvious than it should be.
If yes, what is the correct way to reference or grant access to an external VNet?
Enable the service endpoint on the subnet that accesses Storage:
az network vnet subnet update \
You must provide the full resource ID of the remote subnet.
az storage account network-rule add \
--resource-group <storage-rg> \
--account-name <storage-account> \
--subnet /subscriptions/<consumer-sub-id>/resourceGroups/<your-rg>/providers/Microsoft.Network/virtualNetworks/<your-vnet>/subnets/<subnet-name>
If not, is Private Endpoint the only recommended approach in this scenario?
Since Service Endpoints do work, Private Endpoint is not the only option. but it is the recommended best practice for production workloads.
When to Use Each
- Quick POC / Dev-Test > Service Endpoint
- Cost-sensitive, low-risk workload > Service Endpoint
- Production, compliance-required > Private Endpoint
- Need to disable public access entirely > Private Endpoint (only option)
- Zero Trust architecture > Private Endpoint
- Cross-tenant access > Private Endpoint
Differences:
- Public endpoint can be disabled: Service Endpoint cannot do this; Private Endpoint can.
- Traffic uses private IP only: Service Endpoint still resolves to the public DNS endpoint; Private Endpoint uses a private IP exclusively.
- DNS hijacking protection: Service Endpoint has none; Private Endpoint includes Private DNS Zone integration.
- Works across Azure AD tenants: Service Endpoint requires the same tenant; Private Endpoint works across tenants.
- On-premises access (via ExpressRoute/VPN): Service Endpoint does not support this; Private Endpoint does.
For your cross-subscription scenario, both approaches are valid, choose Service Endpoint for speed and zero cost, or Private Endpoint for maximum security and production readiness.
Are there any best practices or alternative solutions for this type of cross-subscription access restriction?
Best Practice: Private Endpoint (Cross-Subscription)
- Consumer creates Private Endpoint in their VNet targeting the client's Storage Account by resource ID
- Client approves the pending connection
- Configure Private DNS Zone for proper name resolution
- Disable public access on the Storage Account
Official Docs:
- Approve Private Link connections across subscriptions
- Use private endpoints for Azure Storage
- Azure Storage firewall rules – Network security
Kindly let us know if the above helps or you need further assistance on this issue.
Please do not forget to
and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.