Front Door Standard(Managed Identity) fails to access Storage Account with Firewall enabled (403 Error) (Front Door Standard에서 관리 ID를 통해 방화벽이 활성화된 스토리지 접근 시 403 오류 발생)

재형 전 60 평판 포인트
2025-11-25T05:22:01.17+00:00

Summary: Azure Front Door (Standard) fails to access Azure Storage via Managed Identity when Storage Firewall is enabled, resulting in 403 errors, despite correct "Trusted Services" configuration.

Details: I am trying to secure my Storage Account by restricting network access while allowing Front Door (Standard) to fetch content via Managed Identity.

Current Configuration:

  1. Storage Networking: Set to "Selected networks".
  2. Storage Exception: "Allow trusted Microsoft services to access this resource" is CHECKED.
  3. IAM: The Managed Identity used by Front Door has the "Storage Blob Data Reader" role assigned.
  4. Front Door Origin:
  • Protocol: HTTPS Only
  • Auth: Managed Identity (Scope: https://storage.azure.com/.default)
    • Host Header: Correctly matches the storage blob endpoint.

Issue:

  • When Storage Network is set to "All networks", it works perfectly.
  • When set to "Selected networks" (with Trusted Services allowed), it returns HTTP 403 (AuthorizationFailure).
  • I have tried both System-assigned and User-assigned Managed Identities with the same result.
  • I have waited sufficient time for propagation and purged the cache.

Question: According to documentation, Front Door Standard should be able to access restricted Storage via the "Trusted Microsoft Services" exception without needing Private Link (Premium). Please check the backend logs to see why the Managed Identity request is being blocked by the Storage Firewall.

문의 내용 (Description):

1. 문제 요약 (Summary) Azure Front Door (Standard)와 Azure Storage Account를 연동하여 사용 중입니다. Storage Account의 네트워크를 "All networks"로 설정하면 정상 작동하지만, "Selected networks"로 변경하고 "Trusted Microsoft Services" 예외를 허용하면 즉시 403 AuthorizationFailure 오류가 발생합니다. 공식 문서에 따른 관리 ID(Managed Identity) 및 RBAC 설정을 모두 완료했으나 연결되지 않습니다.

2. 환경 정보 (Environment)

  • Front Door SKU: Standard
  • Storage Account Kind: StorageV2 (General Purpose v2)
  • Connection Method: Public Endpoint (Not Private Link)

3. 현재 설정 상태 (Configuration Details) 문제가 되는 상황에서도 아래 설정이 모두 완료되어 있음을 확인했습니다.

  • Front Door Origin Settings:
    • Origin Type: Storage (Azure Blob)
    • Origin Host Header: Matches Storage Account Hostname correctly.
    • Forwarding Protocol: HTTPS Only (Configured correctly).
    • Authentication: Managed Identity (Tested both System-assigned & User-assigned).
    • Scope: https://storage.azure.com/.default
  • Storage Account Settings:
    • Networking: Enabled from selected virtual networks and IP addresses.
    • Firewall Exceptions: Checked "Allow trusted Microsoft services to access this resource".
    • IAM (RBAC): The Managed Identity (used by Front Door) has the "Storage Blob Data Reader" role assigned explicitly to this Storage Account resource.

4. 증상 및 시도한 조치 (Symptoms & Troubleshooting Steps)

  • 네트워크를 Enable from all networks로 변경하면 즉시 정상 접속됨을 확인했습니다. (Front Door 구성 자체에는 문제가 없음)
  • Enable from selected networks 상태에서는 403 AuthorizationFailure 발생.
  • 관리 ID를 "System-assigned"에서 "User-assigned"로 변경하여 테스트했으나 동일 증상.
  • Front Door 캐시 퍼지(Purge All) 및 설정 적용 후 1시간 이상 대기하였으나 해결되지 않음.
  • 브라우저 시크릿 모드에서 테스트 시에도 동일.

5. 문의 사항 (Ask) Front Door Premium 등급의 Private Link 기능을 사용하지 않고, Standard 등급에서 비용 효율적으로 구성하고자 합니다. 공식 문서상 "Trusted Microsoft Services" 예외 처리를 통해 Standard 등급에서도 방화벽 뒤의 스토리지에 접근이 가능해야 하는데, 현재 구성에서 403 오류가 발생하는 원인이 무엇인지, 그리고 백엔드 로그 상에서 차단되는 구체적인 사유(IP 불일치, 헤더 누락 등)를 확인 부탁드립니다.

Azure Virtual Network
Azure Virtual Network

개인 네트워크를 프로비전하고 필요에 따라 온-프레미스 데이터 센터에 연결하는 데 사용되는 Azure 네트워킹 서비스입니다.

댓글 0개 설명 없음

질문 작성자가 수락한 답변
Vallepu Venkateswarlu 10,595 평판 포인트 Microsoft 외부 직원 중재자
2025-11-25T12:01:01.6866667+00:00

Hi @재형 전,

Welcome to Microsoft Q&A Platform.

According to documentation, Front Door Standard should be able to access restricted Storage via the "Trusted Microsoft Services" exception without needing Private Link (Premium).

If you are using the Standard tier, the storage account’s network access must be publicly accessible,either from all networks or from the Front Door IP ranges included in the AzureFrontDoor.Backend service tag.

사용자의 이미지 Ref: Origin security

For the better security, you can configure the AFD with private link feature to access the blob privately without exposing to the public , follow the Secure your origin with Private Link in Azure Front Door Premium

Kindly let us know if the above helps or you need further assistance on this issue. 

Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

이 대답이 도움이 되었나요?

1명이 이 답변이 도움이 된다고 생각했습니다.
댓글 0개 설명 없음

0 추가 답변

정렬 기준: 가장 유용함

답변

질문 작성자는 답변을 '승인됨'으로 표시하고, 중재자는 답변을 '추천됨'으로 표시할 수 있습니다. 이를 통해 사용자는 해당 답변이 작성자의 문제를 해결했다는 것을 알 수 있습니다.