# Private Endpoints and DNS — Azure

Source: https://www.skillbyai.com/en/azure/n-private

> Reach PaaS services over private IPs and resolve their names correctly.

## Taking PaaS services off the public internet

Services such as Storage, Azure SQL, Key Vault and Cosmos DB have public endpoints by default. A **private endpoint** places a network interface with a **private IP from your subnet** for a specific resource, so traffic stays on Microsoft's network and you can disable public network access entirely. The tricky part is **DNS**: clients still use the normal name (`stshopdev123.blob.core.windows.net`), which must now resolve to the private IP. Azure handles this with a CNAME to a `privatelink` name, plus a **private DNS zone** such as `privatelink.blob.core.windows.net` linked to your VNets. Older **service endpoints** are simpler: they route traffic from a subnet to the service over the backbone and let the service firewall allow that subnet, but the service keeps its public IP.

## Private endpoint plus private DNS zone

Without the DNS zone and the zone group, clients would still resolve the public IP.

```bash
SA_ID=$(az storage account show -n stshopdev123 -g rg-shop-dev-cin --query id -o tsv)

az network private-endpoint create -g rg-shop-dev-cin -n pe-st-blob \
  --vnet-name vnet-shop --subnet snet-data \
  --private-connection-resource-id "$SA_ID" --group-id blob --connection-name st-blob

az network private-dns zone create -g rg-shop-dev-cin -n privatelink.blob.core.windows.net
az network private-dns link vnet create -g rg-shop-dev-cin -z privatelink.blob.core.windows.net \
  -n link-shop -v vnet-shop -e false
az network private-endpoint dns-zone-group create -g rg-shop-dev-cin --endpoint-name pe-st-blob \
  -n default --private-dns-zone privatelink.blob.core.windows.net --zone-name blob

az storage account update -n stshopdev123 -g rg-shop-dev-cin --public-network-access Disabled
```

## An internal phone extension

A private endpoint gives the service a desk extension inside your office. People still dial it by name, so the office directory (private DNS) must list the extension, otherwise calls go out to the public number.

**Quiz:** After adding a private endpoint, an app still connects to the storage account's public IP. What is the most likely cause?

- [ ] The storage tier is Cool
- [x] Private DNS zone is missing or not linked to the app's VNet
- [ ] The NSG priority is 100
- [ ] The account uses ZRS

*Answer:* Private DNS zone is missing or not linked to the app's VNet. Name resolution must return the private IP; that needs the privatelink DNS zone linked to the client VNet.
