<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connecting Azure databricks with firewall enabled Azure storage account in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/133507#M4138</link>
    <description>&lt;P&gt;I am having exact issue as&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/176308"&gt;@trailblazer&lt;/a&gt;&amp;nbsp;, that if I enable traffic for all network, I can read/write to storage account, if I only allow selected network, including the VNet, then it doesn't. I am using Serverless setup. I also followed the firewall configuration article mentioned above.&lt;/P&gt;&lt;P&gt;Do I need private endpoint setup? If I recall from my reading, if setting up with VNet injection, private endpoint is not required? I currently only have public and private subnet, but I did not setup any private endpoints.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Oct 2025 20:48:06 GMT</pubDate>
    <dc:creator>mkkao924</dc:creator>
    <dc:date>2025-10-01T20:48:06Z</dc:date>
    <item>
      <title>Connecting Azure databricks with firewall enabled Azure storage account</title>
      <link>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126239#M3717</link>
      <description>&lt;P&gt;Hi I am trying to connect from Azure Databrick workspace to Azure gen2 storage account securely. The storage account is set up with these options&lt;/P&gt;&lt;P&gt;1. &lt;SPAN&gt;Enabled from selected virtual networks and IP addresses- we whitelisted few ips &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Added Microsoft.Databricks/AccessConnector and select the access connector related to this storage account&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. Allow Azure services on the trusted services list to access this storage account.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;With the above settings I am not able to read data from the storage account.&amp;nbsp;If the storage account firewall is opened to all networks then it works but it does not when enable with above settings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i go about restricting only to the necessary Azure Databricks service ? are there any service tags I need to whitelist ?&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 16:53:21 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126239#M3717</guid>
      <dc:creator>trailblazer</dc:creator>
      <dc:date>2025-07-23T16:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting Azure databricks with firewall enabled Azure storage account</title>
      <link>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126240#M3718</link>
      <description>&lt;P&gt;Kyle Hale has an excellent blog post on using the connector:&lt;BR /&gt;&lt;A href="https://medium.com/@kyle.hale/connecting-to-azure-resources-with-managed-identities-in-databricks-47cad4630d53" target="_blank"&gt;https://medium.com/@kyle.hale/connecting-to-azure-resources-with-managed-identities-in-databricks-47cad4630d53&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you have all Kyle has covered, look at the VNet for the ADLS Gen2 to make sure it has connectivity to the VNet your workspace uses.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 17:28:38 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126240#M3718</guid>
      <dc:creator>mnorland</dc:creator>
      <dc:date>2025-07-23T17:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting Azure databricks with firewall enabled Azure storage account</title>
      <link>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126246#M3722</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/176308"&gt;@trailblazer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;So did you configure it something like this? Did you add your access connector to resources instances?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="szymon_dybczak_0-1753294922901.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/18445iA47F4CC0957B803E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="szymon_dybczak_0-1753294922901.png" alt="szymon_dybczak_0-1753294922901.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 18:22:50 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126246#M3722</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-23T18:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting Azure databricks with firewall enabled Azure storage account</title>
      <link>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126286#M3728</link>
      <description>&lt;P&gt;Thanks Szymon,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I have the exact set up as the above and the access connectors are added to the allowed resource instances list and they have contributor role on the storage account.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the above set up, are you able to read/write to the storage account ? For me it is not working unless I "Enable from all network".&lt;/P&gt;&lt;P&gt;Not sure why I get this error message "&lt;SPAN&gt;Please check your Azure Firewall - Full error message: Your request failed with status FAILED: [BAD_REQUEST] This Azure storage request is not authorized. The storage account's 'Firewalls and virtual networks' settings may be blocking access to storage services. Please verify your Azure storage credentials or firewall exception settings&lt;/SPAN&gt;"&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 08:28:37 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126286#M3728</guid>
      <dc:creator>trailblazer</dc:creator>
      <dc:date>2025-07-24T08:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting Azure databricks with firewall enabled Azure storage account</title>
      <link>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126317#M3732</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/176308"&gt;@trailblazer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Yep, in my setup it works as expected. But our environments could be different. I have vnet injected workspace with SCC enabled and private endpoints configured to storage account.&lt;BR /&gt;One question, do you use classic compute or serverless? If you use serverless then you need to configure things bit differently to make it work:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/serverless-network-security/serverless-firewall" target="_blank"&gt;Configure a firewall for serverless compute access - Azure Databricks | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 09:44:21 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/126317#M3732</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-24T09:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting Azure databricks with firewall enabled Azure storage account</title>
      <link>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/133507#M4138</link>
      <description>&lt;P&gt;I am having exact issue as&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/176308"&gt;@trailblazer&lt;/a&gt;&amp;nbsp;, that if I enable traffic for all network, I can read/write to storage account, if I only allow selected network, including the VNet, then it doesn't. I am using Serverless setup. I also followed the firewall configuration article mentioned above.&lt;/P&gt;&lt;P&gt;Do I need private endpoint setup? If I recall from my reading, if setting up with VNet injection, private endpoint is not required? I currently only have public and private subnet, but I did not setup any private endpoints.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 20:48:06 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/connecting-azure-databricks-with-firewall-enabled-azure-storage/m-p/133507#M4138</guid>
      <dc:creator>mkkao924</dc:creator>
      <dc:date>2025-10-01T20:48:06Z</dc:date>
    </item>
  </channel>
</rss>

