Skip to content

Ensure 'Allow Azure services on the trusted services list to access this storage account' is Enabled for Storage Account Access

Why This Matter

When you enable firewall rules on a storage account, all incoming data requests are blocked by default. This includes traffic from critical Azure services like Backup, Site Recovery, Event Grid, and Monitor. If you do not enable the trusted services exception, these services lose access to your storage account, potentially breaking backup operations, logging, and disaster recovery workflows.

What Aether365 Checks

Aether365 verifies that the "Allow Azure services on the trusted services list to access this storage account" setting is enabled for each storage account that uses selected network access. This check appears in your Aether365 dashboard under the azure-storage-accounts compliance section.

Microsoft references

Was this page helpful?