FREE STUDY NOTES · AZ-700

Private endpoint DNS: how privatelink zones resolve a service to its private IP

The CNAME chain from a public service name to a private endpoint, zone groups and zone links.

From Ultra Transcenders AZ-700 by Tony Rough (publishing soon)

A private endpoint is only useful if clients resolve the resource’s normal name to the private IP. Azure does this with privatelink private DNS zones and a CNAME from the public name.

Resource (sub-resource) Private DNS zone
Storage (blob) privatelink.blob.core.windows.net
App Service (sites, Microsoft.Web/sites) privatelink.azurewebsites.net
A client in a VNet looks up the storage account's blob.core.windows.net name. That name is a CNAME to the privatelink.blob.core.windows.net name, which the linked privatelink private zone answers with an A record for the private endpoint's IP. The client then connects to that private IP, and the private endpoint reaches the storage account.
Figure 12.1: How a client in a linked VNet resolves a storage account’s public name to its private endpoint

Common trap: Relying on a private endpoint alone plus a CNAME to an onmicrosoft.com name for a custom private URL - the endpoint alone doesn’t make the custom URL resolve; add a CNAME to the privatelink name and bind the custom domain to the app.

Get the whole book

This note is one section of Ultra Transcenders AZ-700: Designing and Implementing Microsoft Azure Networking Solutions, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · Free AZ-700 glossary · All AZ-700 study notes

More AZ-700 study notes