When a service has a public IP, anyone online can attempt a connection, with authentication and firewall rules deciding who gets in. Private endpoints and service endpoints offer private alternatives.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Public endpoint in context, with comparison tables and the common traps.
Terms in this definition
- Online management group
Workloads that may talk directly to or from the internet, or that need no virtual network at all, go in this management group. It is a sibling of Corp and Local beneath Landing zones.
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
Related terms
- Azure Storage firewall
Network rules on a storage account, applied when public network access is limited to selected networks. Only the listed IP ranges, VNet subnets, resource instances and trusted services can reach the public endpoint; all other traffic is refused.
- Deny public network access
When switched on for an Azure SQL logical server, connections through the public endpoint are refused and clients can only get in through a private endpoint.
- IP firewall rules (Foundry Tools)
Rules permitting particular public IP ranges to reach the public endpoint of Search or a Foundry Tools resource. Because traffic still travels across the internet, this is the weakest form of isolation.
- Public network access
Setting on resources such as storage accounts or Azure Machine Learning workspaces that controls just the public endpoint: open to all networks, limited to selected ones, or off. Turning it off leaves private endpoints working.
- Routing preference
Decides whether internet clients reach a storage account's public endpoint over Microsoft's network, the default, or via internet routing. The choice affects the network path and egress charges, not access rights.
- Service endpoint
Sends a subnet's traffic to an Azure service's public endpoint across the Microsoft backbone, identifying the subnet as the source. It is free, uses no subnet IP addresses and cannot be used from on-premises networks.
- Storage firewall
Restricts a storage account's public endpoint through IP, VNet, resource instance and trusted-service rules. When no rule exists, the endpoint is reachable from any network.