Sends a subnet's traffic to an Azure service's public endpoint across the Microsoft backbone, identifying the subnet as the source. It is free, uses no subnet IP addresses and cannot be used from on-premises networks.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-300AI-103AZ-900
Each book explains Service endpoint in context, with comparison tables and the common traps.
Terms in this definition
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
- Public endpoint
When a service has a public IP, anyone online can attempt a connection, with authentication and firewall rules deciding who gets in. Private endpoints and service endpoints offer private alternatives.
Related terms
- Microsoft.AzureActiveDirectory service endpoint
Older service endpoint tag, relevant only to integrating Data Lake Storage Gen1 with a virtual network. Native service endpoint support doesn't exist for Microsoft Entra ID.
- Microsoft.KeyVault
Namespace of the Key Vault resource provider, with actions such as Microsoft.KeyVault/vaults/write; it is also what the Key Vault service endpoint is called.
- Microsoft.Storage
Namespace for Azure Storage resources, and also the name given to its regional service endpoint. Enabling that endpoint once on a subnet reaches all storage accounts in the same region.
- Microsoft.Storage.Global
Variant of the storage service endpoint that reaches accounts in every region rather than only the local one. A subnet may enable either this or the regional Microsoft.Storage, never both.
- New-AzServiceEndpointPolicy
Cmdlet in Az.Network for creating a service endpoint policy, which limits a subnet's outbound traffic to particular Azure Storage accounts.
- Service endpoint policies
Applied to a subnet's service endpoint to restrict outbound traffic to particular Azure resources, such as specific storage accounts. General availability covers Azure Storage only.
- Virtual network rule
A firewall rule on resources such as Storage or Foundry Tools that lets in one subnet, provided the subnet has the corresponding service endpoint. The rule matters only with a default action of Deny; enabling the endpoint by itself allows nothing.