Drag a concept onto its matching description — or click a concept then click the description.
Create a private endpoint and link the correct private DNS zone to the VNet.
Use a service endpoint on the subnet and allow that subnet in the storage account network rules.
The private DNS zone is missing, not linked to the VNet, or the record has not been populated.
Use a service endpoint with a network rule on the SQL server.
Use the storage firewall with a virtual network rule for AppSubnet; if the on-premises source also needs access, allow its public IP separately. No private endpoint is required.