
Explanation:
Box 1: Infrastructure encryption
Enable infrastructure encryption for double encryption of data
Infrastructure encryption can be enabled for the entire storage account, or for an encryption scope within an account. When infrastructure encryption is enabled for a storage account or an encryption scope, data is encrypted twice - once at the service level and once at the infrastructure level - with two different encryption algorithms and two different keys.
Double encryption of Azure Storage data protects against a scenario where one of the encryption algorithms or keys might be compromised. In this scenario, the additional layer of encryption continues to protect your data.
Box 2: Allow access from
In Firewalls and virtual networks set Allow access from: to Allow public access from specific virtual networks and IP addresses.
Under Exception, check Allow trusted Microsoft services to bypass this firewall.
Reference:
https://learn.microsoft.com/en-us/azure/storage/common/infrastructure-encryption-enable
https://learn.microsoft.com/en-us/azure/databricks/connect/storage/tutorial-azure-storage