This was fixed in #4545 however the storage account stwebcertsTREID is still flagging in Defender due to the policy definition.
Requires an additional attribute adding to terraform to satisfy the policy definition:
network_rules {
default_action = "Deny"
}
