Hi Konstantin Nozdrin,
Welcome to Microsoft Q&A Platform.
I understand your concern. Although the storage account is configured with Selected Networks and the SAP BTP egress IP addresses have been added to the firewall allowlist, access is still failing.
To help identify the root cause and verify whether the traffic is reaching the storage account from the expected source IP addresses, please enable Azure Storage Diagnostic Logs and run the following query in Log Analytics after generating some traffic:
StorageBlobLogs
| summarize RequestCount = count() by CallerIpAddress
| order by RequestCount desc
Please review the CallerIpAddress values returned by the query and verify whether the traffic is originating from the same SAP BTP egress IP addresses that were added to the storage account firewall.
If the traffic is coming from different IP addresses, please coordinate with the SAP BTP team to confirm the complete egress IP range and ensure that all required IP ranges are added to the storage account firewall rather than individual IP addresses.
Note: After enabling diagnostic logs, please allow approximately 30 minutes for the logs to start populating, then generate traffic and run the query.
Please share the results via private message, and we will be happy to assist you further.
Ref: Diagnostic settings in Azure Monitor
Please
and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.