Azure Files delivers fully managed SMB file shares - but by default, storage accounts are reachable from the public internet unless you lock them down. Nerdio Manager makes it straightforward to apply storage firewall rules and restrict access to only the networks and instances you trust.
Important
Firewall rules significantly strengthen your storage account's security posture by controlling who can connect. For an even tighter perimeter, a Private Endpoint keeps traffic on controlled networks instead of the public internet. See Configure Azure Files Network Endpoints on Microsoft Learn for guidance on adding a Private Endpoint to Azure Files.
Even with a Private Endpoint in place, you'll still need to configure the Azure Files firewall to allow your Nerdio Manager instance through. Otherwise, Nerdio Manager features like Auto-scale and backup management won't work as expected.
-
Azure Storage account with file share.
-
NAT Gateway integration configured for your Nerdio Manager instance. For details, see App Service NAT Gateway Integration.
To harden Azure Files:
-
In Nerdio Manager, navigate to your client and open Azure Files.
-
On the storage account, open the Manage drop-down menu, and then select Edit firewall.
The Manage Firewall dialog box opens.
-
Select Enabled from selected virtual networks and IP addresses.
-
Under Virtual networks, select the subnet your AVD session hosts are connected to.
Note
If the selected virtual network doesn't already have the
Microsoft.Storage.Globalservice endpoint enabled, it is created automatically. -
Under Firewall, add the public IP of your Nerdio Manager instance.
-
Under Exceptions, enable the following:
-
Allow Azure services on the trusted services list to access this storage account.
-
Allow read access to storage logging from any network
-
Allow read access to storage metrics from any network
-
-
Select OK.
Important
Nerdio Manager must retain access to the storage account. Without it, Auto-scale and Backup/Restore won't function properly.
Comments (0 comments)