Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
The 403 Forbidden indicates an authorization failure between App Service and the Storage account, even though the managed identity has a data role and networking is open. Use the following checks that map to common 403 causes for Azure Storage:
- Verify the exact error code from Storage logs
- Enable Azure Storage resource logs for the Blob service and check the detailed error code (for example,
AuthorizationPermissionMismatch,AuthorizationFailure, or SAS-related codes). - This will confirm whether the failure is due to missing permissions, wrong service/permissions in SAS, or network/authorization issues.
- Enable Azure Storage resource logs for the Blob service and check the detailed error code (for example,
- Confirm correct data-plane role and scope
- For write operations (backups), the identity must have a role that includes write and list permissions on blobs, such as Storage Blob Data Contributor.
- Ensure the role is assigned at the correct scope (storage account or target container). A role at a different subscription/resource group or wrong account will cause
AuthorizationPermissionMismatch:- For read operations, use Storage Blob Data Reader.
- For write operations, use Storage Blob Data Contributor.
- For management operations, use Storage Blob Data Owner.
- If the error code is
AuthorizationPermissionMismatch, validate that the role scope matches the storage account used by the backup configuration.
- Check if App Service is using SAS and validate SAS settings
- If the backup configuration uses a SAS URL instead of direct identity-based access, validate the SAS token:
- Ensure the SAS has all required permissions for backup: read, write, delete, list (
spfield). - Ensure the SAS
ss(services) includesbfor Blob if backing up to Blob. - Confirm the SAS start (
st) and expiry (se) times are valid and not in the past or too close to current time. Clock skew can cause 403 if the SAS is not yet valid or already expired. - If IP restrictions (
sip) are present in the SAS, remove them or ensure they are not blocking Azure-internal calls. Overly strictsipcan causeAuthorizationFailurewhen the service performs server-side operations.
- Ensure the SAS has all required permissions for backup: read, write, delete, list (
- 403s due to SAS issues are common when the token is expired or not yet valid.
- If the backup configuration uses a SAS URL instead of direct identity-based access, validate the SAS token:
- Validate that public network access and firewall rules are not blocking
- Even with “Enabled from all networks”, confirm:
- Public network access is not disabled at the account level.
- No network security perimeter or service endpoint policy is overriding the firewall and causing 403.
- For public endpoint access, 403 with
AuthorizationFailurecan also appear when:- Public network access is disabled.
- IP address restrictions or virtual network restrictions are in place.
- Firewall rules block the request.
- Even with “Enabled from all networks”, confirm:
- Check for network security perimeter or service endpoint policies
- If the storage account is part of a Network Security Perimeter, its rules override firewall settings and can still cause 403 even when “all networks” is enabled. Use resource logs for the perimeter to identify blocking rules.
- If service endpoint policies exist on the subscription, resource group, or VNet, ensure the storage account is included or remove the restrictive policy. Changes can take up to ~15 minutes to apply.
- Confirm secure transfer and protocol
- If the storage account requires secure transfer, ensure the backup is using HTTPS. Non-HTTPS requests will be rejected with 403.
- General 403 diagnostic checklist for Storage
- Follow the comprehensive checklist for 403 errors:
- Secure transfer (HTTPS) enabled and used.
- Azure RBAC role correct and at proper scope.
- If SAS is used: expiration, permissions, and generation method are correct.
- No conflicting stored access policies.
- No ACL or encryption-scope restrictions blocking access.
- Storage account and subscription are not disabled.
- Follow the comprehensive checklist for 403 errors:
If the detailed error code from Storage logs is AuthorizationPermissionMismatch, focus on RBAC scope and SAS permissions. If it is AuthorizationFailure, focus on network/firewall, public access, IP restrictions, or network security perimeter/service endpoint policies.
References:
- Troubleshoot 403 errors in Azure Blob Storage
- Troubleshoot client application errors in Azure storage accounts
- Monitor, diagnose, and troubleshoot Microsoft Azure Storage (classic)
- Set up Azure App Service access restrictions
- Azure Blob Storage integration with Adobe Experience Manager throws 403 - Microsoft Q&A
- users cannot upload documents to blob storage file share - Microsoft Q&A