A network interface in your subnet whose private IP leads, through Private Link, to a single instance of a service. Peered VNets and on-premises networks (via ExpressRoute or VPN) can use it, after which public access can be switched off.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-300AI-103AZ-900AZ-802
Each book explains Private endpoint in context, with comparison tables and the common traps.
Terms in this definition
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
- Azure Private Link
Azure capability placing PaaS services such as Azure Storage behind a private endpoint in your VNet. Traffic stays on the Microsoft backbone with no public IP involved, though VNet and DNS configuration are required.
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
Related terms
- Deny public network access
When switched on for an Azure SQL logical server, connections through the public endpoint are refused and clients can only get in through a private endpoint.
- IP
The Internet Protocol handles addressing on networks; a private endpoint gives a service its own private IP address.
- Key Vault-linked variable group
Pulls fresh values of selected Key Vault secrets into a pipeline on every run, though keys and certificates are not supported. The service connection must hold Get and List, or the Key Vault Secrets User role; vaults using RBAC behind a private endpoint won't work.
- Private DNS zone group
Child resource of a private endpoint that associates it with as many as five private DNS zones, so its A records are created, updated and removed automatically.
- Private endpoint connection
Kept on the target resource, this record tracks a private endpoint's approval state: Pending, Approved, Rejected or Disconnected. Requests from someone without permission on the resource (another tenant, say) wait as Pending for the owner's approval.
- Private endpoint network policies
Subnet property that is Disabled by default and can be set to NetworkSecurityGroupEnabled, RouteTableEnabled or Enabled. NSGs and UDRs only affect private endpoint traffic once it is on; delegating the subnet does not achieve this.
- Private Link origin
In Azure Front Door Premium, an origin (App Service, Storage or an internal load balancer) reached through a managed private endpoint that Front Door creates and the origin's owner approves.
- privatelink zone
Private DNS zone holding a private endpoint's A record, named after the privatelink CNAME target of the service, for instance privatelink.database.windows.net for Azure SQL Database. Naming it after the public suffix is wrong.