正解:
Storage1 needs to be in the domain.
Note: To register your storage account with AD DS, create an account representing it in your AD DS. You can think of this process as if it were like creating an account representing an on-premises Windows file server in your AD DS. When the feature is enabled on the storage account, it applies to all new and existing file shares in the account.
Reference:
https://docs.microsoft.com/en-us/azure/storage/files/storage-files-identity-ad-ds-enable