← AZ-500: Azure security, historical path
AZ-500 and Azure Security Engineer Associate retired August31,2026. Independent historical content without Microsoft affiliation, accreditation, or certification award. SC-500 has its own syllabus. Editorial review without independent specialist verification. No live Azure changes, access policies, or real containment actions were executed. Fictional cases do not represent internal BNP Paribas policies. Trademarks belong to their respective owners.
02 / 6 · 40 MIN

Network boundaries and private access

Separate routing, resolution, authorization, and enforcement.

Concept and mechanism

A network rule must be interpreted with direction, protocol, ports, source, destination, and priority. In an NSG without other precedence controls, the lower priority number is evaluated first and the first match decides. Existing connection state also matters: removing a rule does not automatically terminate established sessions. A private endpoint provides a private service path but does not automatically block the public endpoint. Validate that control separately. Clients should resolve the normal service name to the appropriate private address; custom or hybrid DNS may need additional configuration before cutover.

Guided application

In App Service, VNet integration supports outbound calls to dependencies; private application ingress needs its own configuration. A classic service endpoint also differs from a Private Endpoint interface for on-premises consumers. For public delivery, Detection-mode WAF observes rules without Prevention blocking. Analyze false positives and scoped exceptions before promoting policy. Confidentiality needs another distinction: ExpressRoute does not encrypt by default merely because the connection is private; MACsec has ExpressRoute Direct scope and is not an automatic property of every circuit. In a project, test allowed and denied paths and preserve evidence of actual resolution and source.

IN PRACTICE

The worker still resolves Blob to a public IP after Private Link. Correct DNS and validate private access before interpreting403 as a missing role.

Common pitfalls

Private IP treated as proof public access is blocked; VNet integration treated as inbound; private circuit treated as encrypted.

Related topics: Identity and temporary privilege · Compute and operational access · Data protection and use

Take this idea with you

Prove each path boundary and keep its effects distinct.

Create account

Reference: Storage private endpoints DNS and public access · AZ-500 objectives2026-01-22; retired2026-08-31