Subnet in which default outbound access is off. Internet access for its VMs must come from a public IP, a NAT gateway or Standard Load Balancer outbound rules.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Private subnet in context, with comparison tables and the common traps.
Terms in this definition
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
- Default outbound access
Outbound internet connectivity Azure gives a VM through a Microsoft-owned public IP when nothing explicit is configured. Private subnets, the default in VNets created from 31 March 2026, don't get it.
- Virtual machines
Infrastructure-as-a-service compute giving complete control of the operating system, making it a fit for lift-and-shift moves and for software relying on OS-level pieces like COM.
- NAT gateway
Gives a subnet managed, outbound-only SNAT through static public IPs and is Microsoft's preferred explicit outbound option. Unsolicited inbound connections are never accepted.
- Azure Load Balancer
Layer-4 load balancer operating within a region, with zone redundancy on the Standard SKU; it has no WAF, doesn't terminate TLS and can't route by URL.
- Outbound rules
With a Standard Load Balancer, these define explicit outbound SNAT so backend pool VMs reach out via the frontend public IPs.