network issue: always get this feedback when loading resource or module in Azure portal, how to fix it?

rain purple 340 Reputation points
2026-05-23T11:29:51.22+00:00

Hello, support team:

  1. cause: when connect to resource or application in Azure portal, sometimes face a loading issue, and use "Self-diagnostics" to check it, get a feedback with" Verify connectivity to Azure domains"
  2. detail information with "Verify connectivity to Azure domains" connectivity to Azure domain how to fix connectivity to Azure domain issue?
  3. influent resource: storage account use "connectivity check"(left side-->help), get a feedback with:
           Endpoint accessible: Yes
    
           List containers: Failed
    
           Failed to list containers: authMode: 1 code: KeyBasedAuthenticationNotPermitted
    
    is it service endpoint issue?
  4. other influent function:
           cannot open queues file in data storage:
    
          ![User's image](/api/attachments/8b454669-adf9-4412-ba0c-7f435d655cba?platform=QnA)
    

Do I need to apply related role? which role I need to apply?

Thank you very much, happy weekend!

user from Azure portal

Azure Storage
Azure Storage

Globally unique resources that provide access to data management services and serve as the parent namespace for the services.

0 comments No comments

Answer accepted by question author
Vallepu Venkateswarlu 10,595 Reputation points Microsoft External Staff Moderator
2026-05-27T19:03:45.99+00:00

Hi rain purple,

Welcome to Microsoft Q&A Platform.

You’re seeing “cannot open queues file in data storage (Error 5 – Access denied)” because your identity doesn’t have data-plane permissions on the storage account. You need to assign an Azure RBAC data role that grants you access to the specific storage service you’re using. Here’s how:

In the Azure portal, go to your Storage Account.

Open “Access control (IAM)” and click “+ Add” → “Add role assignment.”

From the Role list, pick the built-in data role that matches your scenario:

  • Storage Blob Data Reader – read-only access to blob containers.
  • Storage Blob Data Contributor – read/write/delete blobs.
  • Storage Queue Data Reader – peek and read messages in Azure Queue Storage.
  • Storage Queue Data Contributor – add, update, and delete queue messages.
  • Storage File Data SMB Share Reader/Contributor – for Azure Files shares.
  1. Select the scope (subscription, resource group, or storage account) where the resources live.
  2. Assign the role to your user or service principal, and wait a few minutes for propagation.

If you’re using ADLS Gen2, also verify any ACLs on the container or directory under “Containers” → “Access control lists (ACL)”. Once the correct role is in place, retry your operation and you should no longer see the access-denied error.

Please210246-screenshot-2021-12-10-121802.pngand “up-vote” wherever the information provided helps you, **this can be beneficial to other community members.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Anjan Paul 5 Reputation points
    2026-05-23T12:09:21.7466667+00:00

    Hi,

    The root cause of your issue is explicitly stated in your diagnostic log: KeyBasedAuthenticationNotPermitted. This is not a network or service endpoint issue—it is a security configuration and permissions block.

    Here is exactly how to fix it:

    1. Enable Shared Key Access (The Configuration Fix)

    Your Storage Account has disabled account key authentication. The Azure Portal relies on these keys to browse containers and queues unless specifically configured otherwise.

    1. Go to your Storage Account in the Azure Portal.
    2. Under the Settings section on the left menu, click Configuration.
    3. Find Allow storage account key access and change it to Enabled.
    4. Click Save at the top. (Note: It may take up to 5 minutes for this change to replicate).

    2. Assign the Correct Roles (The Identity Fix)

    To view data in the portal (containers and queues) without relying solely on keys, your Azure user account needs explicit data-plane permissions. The standard "Owner" or "Contributor" roles only manage the infrastructure, not the data inside.

    You need to apply the following roles to your user account at the Storage Account level:

    • Storage Blob Data Contributor (Allows you to list, read, and write to blob containers)
    • Storage Queue Data Contributor (Allows you to view and manage queues)

    How to apply the roles:

    1. Navigate to your Storage Account -> Access Control (IAM).
    2. Click + Add -> Add role assignment.
    3. Search for Storage Blob Data Contributor, select it, and click Next.
    4. Assign access to your user account and click Review + assign.
    5. Repeat the exact same steps for Storage Queue Data Contributor.

    Once the configuration is enabled and your roles are assigned, refresh your browser tab, and you will be able to load your modules and list containers perfectly.

    Was this answer helpful?

    0 comments No comments

  2. Vinodh247-1375 44,801 Reputation points Volunteer Moderator
    2026-05-23T12:07:39.61+00:00

    Hi ,

    Thanks for reaching out to Microsoft Q&A.

    This is not a network or service endpoint issue. Your diagnostics already show Endpoint accessible = Yes, so connectivity to Azure domains is fine.

    The real problem is this error: KeyBasedAuthenticationNotPermitted. This means the storage account has disabled shared key (account key) access, and the portal operation you are triggering is still trying to use key-based auth (authMode: 1).

    You must use AAD (RBAC) authentication instead of keys.

    Assign one of these roles on the storage account (or container level):

    • Storage Blob Data Contributor (most common - read/write containers, blobs)
    • Storage Blob Data Reader (readonly)

    Storage Queue Data Contributor (for queues access)

    After role assignment:

    Re-login to Azure portal (or refresh token)

    • Ensure portal is using AAD (not access key / SAS)
    • Retry listing containers/queues

    If still failing: Check storage account setting:

    • Configuration --> Allow shared key access = Disabled (this is expected)

    No need to change unless you want to temporarily allow key-based access (not recommended)

    Bottom line: Issue is RBAC + auth mode mismatch, not networking. Assign proper data-plane roles and use AAD auth. 

    Please 'Upvote'(Thumbs-up) and 'Accept' as answer if the reply was helpful. This will be benefitting other community members who face the same issue.

    Was this answer helpful?

    0 comments No comments

  3. AI answer

    2026-05-23T11:30:14.6133333+00:00

    For the Azure portal “Verify connectivity to Azure domains” failures and the storage account access issues, address them in two parts: portal connectivity and storage permissions.

    1. Fix Azure portal connectivity to Azure domains The error text in Self-diagnostics indicates that the browser can’t reach required Azure portal/Resource Manager endpoints, typically due to network, firewall, VPN, or browser extensions.

    Follow these steps:

    1. Open an InPrivate/Incognito browser session and sign in to the Azure portal again.
    2. Disable all browser extensions and retry the portal operations.
    3. If the issue persists, test from another browser, another device, or another network to see if the problem is specific to one client or network.
    4. On the affected client/network, check for:
      • Corporate proxy or firewall rules that might block access to:
        • Azure portal endpoints (for example, *.portal.azure.com, management.azure.com)
        • Other Microsoft domains used for identity and portal dependencies (for example, *.microsoft.com, *.microsoftonline.com, etc., as listed in the Azure connectivity guidance).
      • VPN or security agents that intercept or block HTTPS traffic.
    5. If the problem continues, capture a browser network trace while reproducing the issue and then open a support case from the Azure portal so Microsoft Support can review the failing calls.

    These steps align with the documented guidance for Application Insights and Azure portal connectivity issues, which are caused by the browser being unable to call required APIs or by network failures.

    1. Fix storage account access and queue/blob listing issues From the screenshots and messages:
    • “KeyBasedAuthenticationNotPermitted” indicates that key-based (account key/SAS) access is disabled on the storage account.
    • “You do not have permissions to list the data using your user account with Microsoft Entra ID” indicates that the signed-in user lacks the necessary Microsoft Entra (Azure AD) permissions for data-plane access.

    To resolve:

    1. Decide which authentication method to use:
      • If the storage account is configured to disallow key-based authentication, use Microsoft Entra ID–based access.
      • If key-based access is required, an administrator must re-enable key-based authentication on the storage account (if allowed by your organization’s policy).
    2. For Microsoft Entra ID access, ensure that the user has appropriate data-plane roles on the storage account, such as:
      • Storage Blob Data Reader/Contributor/Owner for blobs.
      • Storage Queue Data Reader/Contributor/Owner for queues. These roles must be assigned at the storage account, resource group, or subscription scope via Azure role-based access control (RBAC).
    3. After roles are assigned, wait for RBAC propagation and then:
      • In the Azure portal storage blade, choose the “Microsoft Entra user account” authentication method when browsing containers/queues.
      • Retry listing containers/queues.
    4. When to contact support If, after verifying browser extensions, DNS/network connectivity, and firewall/proxy rules, the portal still reports Azure domain connectivity failures, collect a browser trace and open a support request so Microsoft can investigate backend or network issues.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.