Explanation: Box 1: Yes Virtual networks must be in the same region as the service endpoint policy https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies- overview#limitations Box 2: No VNet2 is in SEA Region, so it can only connect to the stoacc in SEA Region through Service Endpoint, which is storage3 Box 3: No Policy allows all storage accounts + IMHO its not full vnet3 to be considered.