Review Trusted Microsoft Services exceptions

Verify the required Azure service connection and data permissions before selecting a trusted-service exception.

Description

If an Azure service depends on a supported trusted-service exception to reach a network-restricted storage account, its integration can fail without that exception. Keeping bypass: 'None' is valid when the account does not need this access.

AzureServices is a network exception for services and operations documented by Microsoft. It does not allow every Azure service or grant data access, so required authentication and permissions must be configured separately.

Potential impact

  • Integrations such as backup or monitoring can stop working if a required service has no access path.
  • Opening the whole network or adding unnecessary exceptions to solve connectivity problems can weaken intended access controls.

Remediation

Check whether the service and operation are on the trusted-service list, and set bypass: 'AzureServices' only when needed. Review defaultAction, public network access, and other exceptions together, and grant minimal data permissions. Verify actual service connectivity and logs; use an alternative private path where appropriate.

Examples

These are network-rule excerpts. Supply actual account inputs and a subnet resource ID, and prepare the subnet and service connectivity prerequisites. The comparison assumes the exception is needed.

Before

bicep
resource storage 'Microsoft.Storage/storageAccounts@2019-06-01' = {
  name: 'storage'
  properties: {
    networkAcls: {
      bypass: 'None'
      virtualNetworkRules: [
        {
          id: 'id'
          action: 'Allow'
        }
      ]
      defaultAction: 'Deny'
    }
  }
}

This retains default denial and the specified virtual network allowance without a trusted-service exception. Whether it is unsuitable depends on the required service's access path.

After

bicep
resource storage 'Microsoft.Storage/storageAccounts@2019-06-01' = {
  name: 'storage'
  properties: {
    networkAcls: {
      bypass: 'AzureServices'
      virtualNetworkRules: [
        {
          id: 'id'
          action: 'Allow'
        }
      ]
      defaultAction: 'Deny'
    }
  }
}

This adds a network exception for documented trusted services while retaining default denial. It does not grant service data permissions or establish that every connection is safe.

References