<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reaching out to Azure Storage with IP from Private VNET pool in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/reaching-out-to-azure-storage-with-ip-from-private-vnet-pool/m-p/137596#M4380</link>
    <description>&lt;P&gt;Yeah, it’s definitely possible for Databricks to hit Azure Storage through a private endpoint without turning on “allow trusted services.” The key is making sure everything’s using the private network path.&lt;/P&gt;&lt;P&gt;Right now, that 10.0.35.x IP you’re seeing is from the Databricks subnet inside your VNet, but it sounds like the storage account traffic is still resolving to the &lt;I&gt;public&lt;/I&gt; endpoint. That’s why it’s getting blocked.&lt;/P&gt;&lt;P&gt;To fix it, make sure:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The Databricks workspace is VNet-injected (not the managed VNet type).&lt;/LI&gt;&lt;LI&gt;You’ve got a &lt;STRONG&gt;Private Endpoint&lt;/STRONG&gt; for your storage account (blob/dfs) in the same VNet or a peered one.&lt;/LI&gt;&lt;LI&gt;The Private DNS zone (like privatelink.blob.core.windows.net or privatelink.dfs.core.windows.net) is linked to the Databricks VNet, so lookups for the storage account resolve to the private IP.&lt;/LI&gt;&lt;LI&gt;NSGs and routes allow traffic between the Databricks and private endpoint subnets.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Once DNS is resolving correctly, Databricks should talk to storage entirely within your VNet, and you can safely keep “trusted services” turned off.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Nov 2025 16:01:11 GMT</pubDate>
    <dc:creator>nayan_wylde</dc:creator>
    <dc:date>2025-11-04T16:01:11Z</dc:date>
    <item>
      <title>Reaching out to Azure Storage with IP from Private VNET pool</title>
      <link>https://community.databricks.com/t5/administration-architecture/reaching-out-to-azure-storage-with-ip-from-private-vnet-pool/m-p/137575#M4376</link>
      <description>&lt;P&gt;Hey All,&lt;/P&gt;&lt;P&gt;Is there a way for Databricks to reach out to Azure Storage using private endpoint?&lt;/P&gt;&lt;P&gt;We would like no omit enabling access by "all trusted services".&lt;/P&gt;&lt;P&gt;All resources are in the same VNET however when Databrics tries to reach out to Storage instead of our 179.x.x.x network we see in the logs that access is blocked and that might be since the ip with which databricks reaches out to storage is from 10.0.35.x pool.&lt;/P&gt;&lt;P&gt;Kindest regards,&lt;/P&gt;&lt;P&gt;Pawel Jarosz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 13:51:53 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/reaching-out-to-azure-storage-with-ip-from-private-vnet-pool/m-p/137575#M4376</guid>
      <dc:creator>zaicnupagadi</dc:creator>
      <dc:date>2025-11-04T13:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Reaching out to Azure Storage with IP from Private VNET pool</title>
      <link>https://community.databricks.com/t5/administration-architecture/reaching-out-to-azure-storage-with-ip-from-private-vnet-pool/m-p/137596#M4380</link>
      <description>&lt;P&gt;Yeah, it’s definitely possible for Databricks to hit Azure Storage through a private endpoint without turning on “allow trusted services.” The key is making sure everything’s using the private network path.&lt;/P&gt;&lt;P&gt;Right now, that 10.0.35.x IP you’re seeing is from the Databricks subnet inside your VNet, but it sounds like the storage account traffic is still resolving to the &lt;I&gt;public&lt;/I&gt; endpoint. That’s why it’s getting blocked.&lt;/P&gt;&lt;P&gt;To fix it, make sure:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The Databricks workspace is VNet-injected (not the managed VNet type).&lt;/LI&gt;&lt;LI&gt;You’ve got a &lt;STRONG&gt;Private Endpoint&lt;/STRONG&gt; for your storage account (blob/dfs) in the same VNet or a peered one.&lt;/LI&gt;&lt;LI&gt;The Private DNS zone (like privatelink.blob.core.windows.net or privatelink.dfs.core.windows.net) is linked to the Databricks VNet, so lookups for the storage account resolve to the private IP.&lt;/LI&gt;&lt;LI&gt;NSGs and routes allow traffic between the Databricks and private endpoint subnets.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Once DNS is resolving correctly, Databricks should talk to storage entirely within your VNet, and you can safely keep “trusted services” turned off.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 16:01:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/reaching-out-to-azure-storage-with-ip-from-private-vnet-pool/m-p/137596#M4380</guid>
      <dc:creator>nayan_wylde</dc:creator>
      <dc:date>2025-11-04T16:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Reaching out to Azure Storage with IP from Private VNET pool</title>
      <link>https://community.databricks.com/t5/administration-architecture/reaching-out-to-azure-storage-with-ip-from-private-vnet-pool/m-p/140662#M4569</link>
      <description>&lt;P&gt;Sorry for late reply - thank you for your help Nayan!&lt;/P&gt;</description>
      <pubDate>Sun, 30 Nov 2025 19:01:14 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/reaching-out-to-azure-storage-with-ip-from-private-vnet-pool/m-p/140662#M4569</guid>
      <dc:creator>zaicnupagadi</dc:creator>
      <dc:date>2025-11-30T19:01:14Z</dc:date>
    </item>
  </channel>
</rss>

