Summary: Azure Front Door (Standard) fails to access Azure Storage via Managed Identity when Storage Firewall is enabled, resulting in 403 errors, despite correct "Trusted Services" configuration.
Details: I am trying to secure my Storage Account by restricting network access while allowing Front Door (Standard) to fetch content via Managed Identity.
Current Configuration:
- Storage Networking: Set to "Selected networks".
- Storage Exception: "Allow trusted Microsoft services to access this resource" is CHECKED.
- IAM: The Managed Identity used by Front Door has the "Storage Blob Data Reader" role assigned.
- Front Door Origin:
- Protocol: HTTPS Only
- Auth: Managed Identity (Scope:
https://storage.azure.com/.default)
- Host Header: Correctly matches the storage blob endpoint.
Issue:
- When Storage Network is set to "All networks", it works perfectly.
- When set to "Selected networks" (with Trusted Services allowed), it returns HTTP 403 (AuthorizationFailure).
- I have tried both System-assigned and User-assigned Managed Identities with the same result.
- I have waited sufficient time for propagation and purged the cache.
Question: According to documentation, Front Door Standard should be able to access restricted Storage via the "Trusted Microsoft Services" exception without needing Private Link (Premium). Please check the backend logs to see why the Managed Identity request is being blocked by the Storage Firewall.
문의 내용 (Description):
1. 문제 요약 (Summary) Azure Front Door (Standard)와 Azure Storage Account를 연동하여 사용 중입니다. Storage Account의 네트워크를 "All networks"로 설정하면 정상 작동하지만, "Selected networks"로 변경하고 "Trusted Microsoft Services" 예외를 허용하면 즉시 403 AuthorizationFailure 오류가 발생합니다. 공식 문서에 따른 관리 ID(Managed Identity) 및 RBAC 설정을 모두 완료했으나 연결되지 않습니다.
2. 환경 정보 (Environment)
- Front Door SKU: Standard
- Storage Account Kind: StorageV2 (General Purpose v2)
- Connection Method: Public Endpoint (Not Private Link)
3. 현재 설정 상태 (Configuration Details) 문제가 되는 상황에서도 아래 설정이 모두 완료되어 있음을 확인했습니다.
- Front Door Origin Settings:
- Origin Type: Storage (Azure Blob)
- Origin Host Header: Matches Storage Account Hostname correctly.
- Forwarding Protocol: HTTPS Only (Configured correctly).
- Authentication: Managed Identity (Tested both System-assigned & User-assigned).
- Scope:
https://storage.azure.com/.default
- Storage Account Settings:
- Networking: Enabled from selected virtual networks and IP addresses.
- Firewall Exceptions: Checked "Allow trusted Microsoft services to access this resource".
- IAM (RBAC): The Managed Identity (used by Front Door) has the "Storage Blob Data Reader" role assigned explicitly to this Storage Account resource.
4. 증상 및 시도한 조치 (Symptoms & Troubleshooting Steps)
- 네트워크를
Enable from all networks로 변경하면 즉시 정상 접속됨을 확인했습니다. (Front Door 구성 자체에는 문제가 없음)
-
Enable from selected networks 상태에서는 403 AuthorizationFailure 발생.
- 관리 ID를 "System-assigned"에서 "User-assigned"로 변경하여 테스트했으나 동일 증상.
- Front Door 캐시 퍼지(Purge All) 및 설정 적용 후 1시간 이상 대기하였으나 해결되지 않음.
- 브라우저 시크릿 모드에서 테스트 시에도 동일.
5. 문의 사항 (Ask) Front Door Premium 등급의 Private Link 기능을 사용하지 않고, Standard 등급에서 비용 효율적으로 구성하고자 합니다. 공식 문서상 "Trusted Microsoft Services" 예외 처리를 통해 Standard 등급에서도 방화벽 뒤의 스토리지에 접근이 가능해야 하는데, 현재 구성에서 403 오류가 발생하는 원인이 무엇인지, 그리고 백엔드 로그 상에서 차단되는 구체적인 사유(IP 불일치, 헤더 누락 등)를 확인 부탁드립니다.