How to properly restrict public network access on Azure Databricks Managed Root Storage?

mariof
New Contributor

Hi,

Our main goal right now is to disable public network access on the Managed Root Storage Account (the one created automatically in the managed resource group dbresources... which contains containers like ephemeral, root, meta, and unity-catalog-storage).

When reviewing the Networking tab of this specific storage account in the Azure Portal, it is currently configured as "Enabled from all networks".

I created 2 private endpoints (dfs, blob) in  Managed Root Storage Account .Could this be the final solution to restrict public access, or what are the next steps I need to follow?

We currently have Serverless Compute and Clasic Compute (No serverless).

Just to clarify, we are not talking about external business data storage, but strictly about the workspace system root storage (dbstorageiq..)