Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
Hi,
I think this is result of this limitation:
"By design, access to a storage account from trusted services takes the highest precedence over other network access restrictions. If you set Public network access to Disabled after previously setting it to Enabled from selected virtual networks and IP addresses, any resource instances and exceptions that you previously configured, including Allow Azure services on the trusted services list to access this storage account, will remain in effect. As a result, those resources and services might still have access to the storage account."
Restrictions and considerations
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.