{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/",
        "slug": "dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/"
        },
        "title": "Check for an unsupported subnet storage policy before retrying Elastic SAN iSCSI login",
        "summary": "Elastic SAN rejects connections from subnets with Storage service endpoint policies even when other endpoint rules are correct.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:15+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 232,
        "potentially_affected": "Elastic SAN connections originating from subnets associated with Storage service endpoint policies.",
        "dse_recommendation": "Inspect the subnet policy association and evaluate a dedicated supported subnet before relaxing existing controls.",
        "primary_source": {
            "name": "Troubleshoot Azure Elastic SAN | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-troubleshoot",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Elastic SAN does not support subnets that have Storage service endpoint policies. Microsoft states that all iSCSI connections from such subnets are blocked even if service endpoints and network rules are correctly configured. The policy&#8217;s allowlist does not include Elastic SAN iSCSI targets.</p>\n<p>The documented remedies are removing that policy from the SAN client subnet or using a dedicated subnet without it. Microsoft also requires confirming that the Microsoft.Storage.Global service endpoint remains enabled after changes. <a href=\"https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-troubleshoot\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the actual originating subnet and its policy association. Keep this unsupported network combination separate from identity failures, iSCSI digest compatibility and independent endpoint misconfiguration.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends reviewing a dedicated supported subnet with the network owner before removing a shared policy. Determine which other storage access the existing policy protects and preserve that boundary in the approved design. Do not repeatedly add destinations to an allowlist as though this unsupported SAN combination were an ordinary missing-entry problem.</p>\n<h2>Verification</h2>\n<p>In an approved test, inspect the originating subnet, service endpoint and applicable network rules before attempting the connection. After the selected correction, verify the intended SAN login and relevant storage restrictions from each affected subnet. Retain both connectivity and protection evidence. A successful login should not close the change until any impact on previously policy-restricted storage paths is understood.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-troubleshoot\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Troubleshoot Azure Elastic SAN</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nElastic SAN does not support subnets that have Storage service endpoint policies. Microsoft states that all iSCSI connections from such subnets are blocked even if service endpoints and network rules are correctly configured. The policy’s allowlist does not include Elastic SAN iSCSI targets.\nThe documented remedies are removing that policy from the SAN client subnet or using a dedicated subnet without it. Microsoft also requires confirming that the Microsoft.Storage.Global service endpoint remains enabled after changes. Microsoft Learn.\nApplicability\nIdentify the actual originating subnet and its policy association. Keep this unsupported network combination separate from identity failures, iSCSI digest compatibility and independent endpoint misconfiguration.\nDSE recommendation\nDSE recommends reviewing a dedicated supported subnet with the network owner before removing a shared policy. Determine which other storage access the existing policy protects and preserve that boundary in the approved design. Do not repeatedly add destinations to an allowlist as though this unsupported SAN combination were an ordinary missing-entry problem.\nVerification\nIn an approved test, inspect the originating subnet, service endpoint and applicable network rules before attempting the connection. After the selected correction, verify the intended SAN login and relevant storage restrictions from each affected subnet. Retain both connectivity and protection evidence. A successful login should not close the change until any impact on previously policy-restricted storage paths is understood.\nOfficial references\nMicrosoft Learn: Troubleshoot Azure Elastic SAN. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nElastic SAN does not support subnets that have Storage service endpoint policies. Microsoft states that all iSCSI connections from such subnets are blocked even if service endpoints and network rules are correctly configured. The policy’s allowlist does not include Elastic SAN iSCSI targets.\n\nThe documented remedies are removing that policy from the SAN client subnet or using a dedicated subnet without it. Microsoft also requires confirming that the Microsoft.Storage.Global service endpoint remains enabled after changes. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-troubleshoot).\n\n## Applicability\n\nIdentify the actual originating subnet and its policy association. Keep this unsupported network combination separate from identity failures, iSCSI digest compatibility and independent endpoint misconfiguration.\n\n## DSE recommendation\n\nDSE recommends reviewing a dedicated supported subnet with the network owner before removing a shared policy. Determine which other storage access the existing policy protects and preserve that boundary in the approved design. Do not repeatedly add destinations to an allowlist as though this unsupported SAN combination were an ordinary missing-entry problem.\n\n## Verification\n\nIn an approved test, inspect the originating subnet, service endpoint and applicable network rules before attempting the connection. After the selected correction, verify the intended SAN login and relevant storage restrictions from each affected subnet. Retain both connectivity and protection evidence. A successful login should not close the change until any impact on previously policy-restricted storage paths is understood.\n\n## Official references\n\n[Microsoft Learn: Troubleshoot Azure Elastic SAN](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-troubleshoot). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check for an unsupported subnet storage policy before retrying Elastic SAN iSCSI login",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/",
                "headline": "Check for an unsupported subnet storage policy before retrying Elastic SAN iSCSI login",
                "description": "Elastic SAN rejects connections from subnets with Storage service endpoint policies even when other endpoint rules are correct.",
                "abstract": "Elastic SAN rejects connections from subnets with Storage service endpoint policies even when other endpoint rules are correct.",
                "articleBody": "Source facts\nElastic SAN does not support subnets that have Storage service endpoint policies. Microsoft states that all iSCSI connections from such subnets are blocked even if service endpoints and network rules are correctly configured. The policy’s allowlist does not include Elastic SAN iSCSI targets.\nThe documented remedies are removing that policy from the SAN client subnet or using a dedicated subnet without it. Microsoft also requires confirming that the Microsoft.Storage.Global service endpoint remains enabled after changes. Microsoft Learn.\nApplicability\nIdentify the actual originating subnet and its policy association. Keep this unsupported network combination separate from identity failures, iSCSI digest compatibility and independent endpoint misconfiguration.\nDSE recommendation\nDSE recommends reviewing a dedicated supported subnet with the network owner before removing a shared policy. Determine which other storage access the existing policy protects and preserve that boundary in the approved design. Do not repeatedly add destinations to an allowlist as though this unsupported SAN combination were an ordinary missing-entry problem.\nVerification\nIn an approved test, inspect the originating subnet, service endpoint and applicable network rules before attempting the connection. After the selected correction, verify the intended SAN login and relevant storage restrictions from each affected subnet. Retain both connectivity and protection evidence. A successful login should not close the change until any impact on previously policy-restricted storage paths is understood.\nOfficial references\nMicrosoft Learn: Troubleshoot Azure Elastic SAN. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:22:15+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-581-check-for-an-unsupported-subnet-storage-policy-before-retrying-elastic-san-iscsi/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check for an unsupported subnet storage policy before retrying Elastic SAN iSCSI login"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 232,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Troubleshoot Azure Elastic SAN | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-troubleshoot"
                }
            }
        ]
    }
}