Create a secure environment in Azure by forcing all storage traffic through Private IPs.
With this the Azure Storage Endpoint gets a Private IP assigned, and the Hosting Connection traffic cannot go through the public internet; all traffic needs to go through a Private IP.
Check the option 'Route traffic through Citrix Cloud Connectors' under Hosting Connection properties. All other configurations are done in Azure.
For additional security, the traffic can be restricted only from Cloud Connector IPs. Again the restrictions also need to be configured in Azure.
Ref: https://learn.microsoft.com/en-us/azure/virtual-machines/policy-reference