Enabled System ID in AFD to access blob containers - no access

Matthew Barrett 176 Reputation points
2026-04-10T15:40:21.09+00:00

I followed the instructions https://learn.microsoft.com/en-us/azure/frontdoor/origin-authentication-with-managed-identities and configured based on anonymous access. I am unable to access the blobs now even with anonymous access still enabled.

I have AFD Standard and a storage account in the same resource group and I want Internet traffic to be allowed only via AFD interface. Currently, anonymous blobs are accessible via the blob URI (i.e. https://media.blob.core.windows.net).

Azure Front Door
Azure Front Door

An Azure service that provides a cloud content delivery network with threat protection.


Answer accepted by question author
Vallepu Venkateswarlu 10,595 Reputation points Microsoft External Staff Moderator
2026-04-10T18:44:21.31+00:00

Hi @ Matthew Barrett,

As discussed offline, IF you want to access Storage account Privately from AFD Endpoint without premium SKU, it wont work as Private link support only Premium SKU's in Azure Front door, Refer these link.

If you want to restrict access to only Azure Front Door (AFD) and selected virtual networks, disable public access on the storage account. Then configure a private endpoint within the VNet and enable Private Link for AFD.

 

It will create two private endpoints for access from the VNet and one private endpoint for access from the AFD side only.

Only Option to access from AFD is storage should be in Public access.

Please ensure that the Storage Blob Data Contributor or Storage Blob Data Reader role has been assigned to the AFD system identity and confirm.

I have configured Azure Front Door with a Storage Blob as the origin to access it via the AFD endpoint. The storage account has been created with public access enabled, along with Microsoft Entra authorization and blob anonymous access enabled, as shown below, to allow public access

User's image

Note: Anonymous access is not recommended for production environments due to security concerns. Kindly disable anonymous access and enable private access.

Once these changes are applied, please configure the container authentication method to use Microsoft Entra ID for secure access via the AFD endpoint.
User's image

Please verify that origin authentication is enabled and set to System Managed Identity. Also, ensure that the Storage Blob Data Contributor role is assigned to the AFD identity. Additionally, confirm that the origin protocol is configured to use HTTPS.

User's image

AFD route Configuration, Make sure Pattern to Match should be /* (to access all request)

User's image

After completing all configurations, please wait for 10 minutes for the changes to propagate, and then verify the result.

Please find my AFD result below.

User's image

If above steps are nor resolve your issue, Please share the requested details in Private message for further connectivity.

Please210246-screenshot-2021-12-10-121802.pngand “up-vote” wherever the information provided helps you, this can be beneficial to other community members

Was this answer helpful?

0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Matthew Barrett 176 Reputation points
    2026-06-05T14:47:01.1533333+00:00

    The storage account provides docs and images for an anonymous website and access must be set to anonymous as we cannot afford to use AFD Premium for the configuration you've provided.

    Thanks anyways.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.