This diagram provides a visual overview of the different mechanisms used to control access to Azure Storage resources. It details how identity-based access (Azure Active Directory, Shared Access Signatures) and network-based access (VNet service endpoints, Private Endpoints, Firewall rules) work in conjunction to secure your data.
Understanding these controls is crucial for implementing robust security for your blobs, files, queues, and tables stored in Azure.