Check for an unsupported subnet storage policy before retrying Elastic SAN iSCSI login

Elastic SAN rejects connections from subnets with Storage service endpoint policies even when other endpoint rules are correct.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Elastic SAN rejects connections from subnets with Storage service endpoint policies even when other endpoint rules are correct.

Potentially affected

Elastic SAN connections originating from subnets associated with Storage service endpoint policies.

DSE recommendation

Inspect the subnet policy association and evaluate a dedicated supported subnet before relaxing existing controls.

Source facts

Elastic SAN does not support subnets that have Storage service endpoint policies. Microsoft states that all iSCSI connections from such subnets are blocked even if service endpoints and network rules are correctly configured. The policy’s allowlist does not include Elastic SAN iSCSI targets.

The documented remedies are removing that policy from the SAN client subnet or using a dedicated subnet without it. Microsoft also requires confirming that the Microsoft.Storage.Global service endpoint remains enabled after changes. Microsoft Learn.

Applicability

Identify the actual originating subnet and its policy association. Keep this unsupported network combination separate from identity failures, iSCSI digest compatibility and independent endpoint misconfiguration.

DSE recommendation

DSE recommends reviewing a dedicated supported subnet with the network owner before removing a shared policy. Determine which other storage access the existing policy protects and preserve that boundary in the approved design. Do not repeatedly add destinations to an allowlist as though this unsupported SAN combination were an ordinary missing-entry problem.

Verification

In an approved test, inspect the originating subnet, service endpoint and applicable network rules before attempting the connection. After the selected correction, verify the intended SAN login and relevant storage restrictions from each affected subnet. Retain both connectivity and protection evidence. A successful login should not close the change until any impact on previously policy-restricted storage paths is understood.

Official references

Microsoft Learn: Troubleshoot Azure Elastic SAN. Source retrieved September 9, 2026.

Primary reference

Review the official source

Troubleshoot Azure Elastic SAN | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE