Both lock an Azure service down to your virtual network, but they work in completely different ways. How each one works, the on-premises trap, DNS, data exfiltration, and a five-second way to choose.
By Tony Rough
You want a storage account (or a SQL database, or a key vault) to be reachable only from your own virtual network. Azure gives you two ways to do it: a service endpoint or a private endpoint. The names are nearly identical; the way they work is not, and exam questions are built on the difference.
Everything else follows from that.
You switch a service endpoint on per subnet, per service: for example Microsoft.Storage on Subnet A. From then on:
A private endpoint is a network interface in your subnet with a private IP address, say 10.0.1.5, connected through Azure Private Link to one resource: this storage account, not every storage account in Azure.
privatelink.blob.core.windows.net makes the account’s normal name resolve to 10.0.1.5 instead of the public address, so applications don’t change their connection strings.Service endpoints only work for traffic that starts in an Azure subnet that has them switched on. Traffic arriving from on-premises over a VPN or ExpressRoute can’t use them. If on-premises clients must reach the service, the only service-endpoint answer is to allow your on-premises public (NAT) IP addresses in the service’s firewall, which is no longer private access.
A private endpoint is just an IP address in your virtual network, so anything that can route to the virtual network can reach it: on-premises networks over VPN or ExpressRoute, and peered virtual networks.
So when a requirement says “on-premises users must reach the storage account privately” or “over ExpressRoute private peering”, the answer is a private endpoint.
blob.core.windows.net, not the privatelink zone) to an Azure DNS Private Resolver inbound endpoint.| You need… | Choose |
|---|---|
| Free and simple, and only Azure subnets need access | Service endpoint |
| Private access from on-premises or peered networks | Private endpoint |
| Public network access switched off completely | Private endpoint |
| Protection against data being copied to other accounts | Private endpoint |
| …and whenever you choose a private endpoint | check the DNS |
Microsoft’s own guidance leans towards Private Link for new designs, because of the on-premises and exfiltration advantages, but service endpoints remain a valid, free answer when the requirements are simple.
Private access has a chapter of its own in the AZ-700 study guide (chapter 12, with private endpoint DNS covered again in the DNS chapter). It’s in chapter 12 of the AZ-104 study guide, the networking chapter of the AZ-305 study guide and chapter 8 of the SC-500 study guide, each with the traps called out like these. Facts checked against Microsoft Learn on 4 October 2026.
Four Azure services balance traffic, and two questions tell them apart: is it web traffic that needs layer 7, and is it regional or global? Each service on a 2x2 grid, plus three exam traps.
Six redundancy options, four acronyms and one trap that catches almost everyone. The two questions that pick the right Azure Storage option every time, plus the read-access trap and three more.
Azure has two separate role systems. Azure roles control resources; Microsoft Entra roles control the directory. Scopes and inheritance, Owner vs Contributor vs User Access Administrator, elevate access, and three traps.
Microsoft has pushed the retirement of Application Insights URL ping tests back to September 2028 and announced that Azure IoT Central retires in September 2029. Automatic zone placement for scale sets, and Microsoft Entra Kerberos for Azure NetApp Files, are now in preview.
Four Microsoft certification study guides are out, three more are on the way, and there's now a free glossary for the whole series. Here's what the books are, how they're different, and what's free on this site.