From what you describe you restricted network traffic to the storage account.
You need to allow app services to access it.
The option "Allow trusted Microsoft Services" does not include App Services:
You need to integrate the storage account and the app service into a virtual network either using service endpoints or private endpoints.