How to connect SAP BTP Integration Suite(deployed in Azure) to Azure Storage

Konstantin Nozdrin 5 Reputation points
2026-06-10T14:02:49.42+00:00

Hello,

I`m trying to connect BTP Integration Suite (deployed in Azure) to Azure Fileshare via SAP Integration Suite Azure Storage adapter. In adapter itself I configured only Storage Account name, share name and credentials, so I suppose it uses some predefined URL(like <storage>.file.core.windows.net). It works fine when public access is not restricted. But when I whitelist all SAP BTP egress IPs connection fails with error:

This request is not authorized to perform this operation.

I assume connection is not going via public internet, but rather via Azure/MS only network.

How could it be configured securely to ensure successfull connection from SAP BTP Integration Suite to Azure Storage/Fileshare

Konstantin

Azure Storage
Azure Storage

Globally unique resources that provide access to data management services and serve as the parent namespace for the services.


Answer recommended by moderator
Konstantin Nozdrin 5 Reputation points
2026-09-21T13:14:56.28+00:00

Hello all,

SAP confirmed that in case both BTP IS and Azure storage are located in the same region and hosted in Azure(for Azure storage it is obvious...) it will not use public network. Also SAP can`t provide VN details to be used in whitelist..

So another option should be used.

Thanks all for help!

Konstantin

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Oldest
  1. Vallepu Venkateswarlu 10,595 Reputation points Microsoft External Staff Moderator
    2026-06-10T15:44:57.2533333+00:00

    Hi Konstantin Nozdrin,

    Welcome to Microsoft Q&A Platform.

    I understand your concern. Although the storage account is configured with Selected Networks and the SAP BTP egress IP addresses have been added to the firewall allowlist, access is still failing.

    To help identify the root cause and verify whether the traffic is reaching the storage account from the expected source IP addresses, please enable Azure Storage Diagnostic Logs and run the following query in Log Analytics after generating some traffic:

    StorageBlobLogs
    | summarize RequestCount = count() by CallerIpAddress
    | order by RequestCount desc
    

    Please review the CallerIpAddress values returned by the query and verify whether the traffic is originating from the same SAP BTP egress IP addresses that were added to the storage account firewall.

    If the traffic is coming from different IP addresses, please coordinate with the SAP BTP team to confirm the complete egress IP range and ensure that all required IP ranges are added to the storage account firewall rather than individual IP addresses.

    Note: After enabling diagnostic logs, please allow approximately 30 minutes for the logs to start populating, then generate traffic and run the query.

    Please share the results via private message, and we will be happy to assist you further.

    Ref: Diagnostic settings in Azure Monitor

    Please 210246-screenshot-2021-12-10-121802.pngand “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    Was this answer helpful?

    2 people found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.