A zone in Azure DNS for private records (A records, for example), linked to VNets. Because only 168.63.129.16 resolves it, clients on-premises must go through a DNS forwarder or Azure DNS Private Resolver.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AZ-900
Each book explains Private DNS zone in context, with comparison tables and the common traps.
Terms in this definition
- Azure DNS
Family of Azure services for hosting and resolving DNS, covering public zones, private zones and DNS Private Resolver; you can't register domain names through it.
- 168.63.129.16
Special platform address (WireServer) through which Azure delivers the VM agent channel, built-in DNS, DHCP and load balancer health probes. Traffic to it must stay open, or those platform functions stop working.
- DNS
The system that turns names into addresses. In Azure, private endpoints depend on private DNS zones, which are queried through 168.63.129.16.
- Azure DNS Private Resolver
Managed resolver inside a VNet that removes the need for DNS server VMs in hybrid setups. Its inbound and outbound endpoints each need their own subnet of at least /28 delegated to
Microsoft.Network/dnsResolvers, and it can link only to a VNet in the same region.
Related terms
- Autoregistration
When enabled on a private DNS zone's virtual network link, VMs in that VNet get A records created automatically, kept in step as their IPs change and removed when they are deleted. A VNet may autoregister into only one private zone.
- Private endpoint DNS zone
Each service has its own private DNS zone where private endpoints register, for example privatelink.blob.core.windows.net (Blob), privatelink.database.windows.net (SQL), privatelink.documents.azure.com (Cosmos DB) or privatelink.azurewebsites.net (App Service).
- privatelink zone
Private DNS zone holding a private endpoint's A record, named after the privatelink CNAME target of the service, for instance privatelink.database.windows.net for Azure SQL Database. Naming it after the public suffix is wrong.
- PTR record
DNS record used for reverse lookups, resolving an IP address back to a name. Private DNS zone autoregistration does not create these.
- Registration virtual network
VNet whose link to a private DNS zone has autoregistration turned on. A single zone may have many such VNets, yet each VNet registers in just one zone, with any further links limited to resolution.
- Virtual network link
Connects a private DNS zone to a VNet so the VNet can resolve names (a resolution-only link) or register records (with autoregistration on). Peering on its own provides neither.