An option could be if Microsoft would publish Azure subnet IDs from which Business central traffic originates. Those subnet IDs could then be whitelisted (using Azure CLI or PowerShell) in the storage account firewall.
Please consider this idea for product update feature needed as shortened the time for Copilot Credits consumption to be written into Power Platform Admin Center downloadable report.