From the Basic tier up, App Service can send outbound traffic into a VNet by way of a subnet delegated to Microsoft.Web/serverFarms. Reaching the app privately from inside, though, calls for a private endpoint.
Also called VNet integration.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Regional VNet integration in context, with comparison tables and the common traps.
Terms in this definition
- Basic
Low-cost Log Analytics table plan where ingestion is cheap but each query is charged per GB and runs at workspace scope. Full KQL and simple log search alerts are supported; standard log search alerts are not.
- Archive
Offline access tier for blobs, cheapest to store yet dearest to access. Reading a blob means rehydrating it first, which can take as long as 15 hours.
- App Service
Managed PaaS hosting for web apps and Web App for Containers, run in a sandbox without OS access. Deployment slots and autoscale start at the Standard tier.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Private endpoint
A network interface in your subnet whose private IP leads, through Private Link, to a single instance of a service. Peered VNets and on-premises networks (via ExpressRoute or VPN) can use it, after which public access can be switched off.
Related terms
- Azure Functions Consumption plan
Older serverless hosting plan for Functions that caps each run at 10 minutes and lacks both VNet integration and inbound private endpoints, all of which Flex Consumption, Premium and Dedicated plans provide.
- Azure Functions Premium plan
Functions hosting plan that keeps instances pre-warmed to avoid cold starts and supports VNet integration; executions default to 30 minutes, a limit you can raise in host.json.
- Consumption
Serverless, event-driven Azure Functions hosting plan charged per execution; runs are capped at 10 minutes and VNet integration isn't available.
- Dedicated
Running Azure Functions on an App Service plan, which removes the execution time limit and offers VNet integration on Basic and higher tiers.
- Gateway-required VNet integration
Legacy option letting App Service reach VNets located in a different region, by connecting over an SSTP point-to-site VPN into a route-based virtual network gateway. Because it carries extra gateway charges, it is being retired on 31 March 2027 and regional VNet integration replaces it.
- MPSJ
Multi-plan subnet join, an App Service capability that lets multiple App Service plans within one subscription use the same VNet integration subnet. That subnet needs a size of /26 or larger.
- Premium
Hosting plan for Azure Functions that keeps instances pre-warmed to avoid cold starts and supports VNet integration. Executions time out after 30 minutes by default, which host.json can extend.
- Subnet delegation
Hands a subnet over to one Azure service; App Service VNet integration, for instance, uses Microsoft.Web/serverFarms. VMs or other resources must not already be in it.