Did you know Resource instance rules for access to Azure Storage are now in public preview in all Azure public regions.
Some Azure resources cannot be isolated through a virtual network or an IP address rule. However, you'd still like to secure and restrict access to your storage account to only your application's Azure resources. You can now configure your storage accounts to allow access to only specific resource instances of select Azure services by creating a resource instance rule
for more information you refer to the MS documentation
Accessing resource instance rules
Managing virtual network rules
To modify vnet rules, simply select either add exiting network or create new network and apply the rule accordingly