Concept and mechanism
A network rule must be interpreted with direction, protocol, ports, source, destination, and priority. In an NSG without other precedence controls, the lower priority number is evaluated first and the first match decides. Existing connection state also matters: removing a rule does not automatically terminate established sessions. A private endpoint provides a private service path but does not automatically block the public endpoint. Validate that control separately. Clients should resolve the normal service name to the appropriate private address; custom or hybrid DNS may need additional configuration before cutover.
Guided application
In App Service, VNet integration supports outbound calls to dependencies; private application ingress needs its own configuration. A classic service endpoint also differs from a Private Endpoint interface for on-premises consumers. For public delivery, Detection-mode WAF observes rules without Prevention blocking. Analyze false positives and scoped exceptions before promoting policy. Confidentiality needs another distinction: ExpressRoute does not encrypt by default merely because the connection is private; MACsec has ExpressRoute Direct scope and is not an automatic property of every circuit. In a project, test allowed and denied paths and preserve evidence of actual resolution and source.
The worker still resolves Blob to a public IP after Private Link. Correct DNS and validate private access before interpreting403 as a missing role.
Common pitfalls
Private IP treated as proof public access is blocked; VNet integration treated as inbound; private circuit treated as encrypted.
Related topics: Identity and temporary privilege · Compute and operational access · Data protection and use
Prove each path boundary and keep its effects distinct.
Reference: Storage private endpoints DNS and public access · AZ-500 objectives2026-01-22; retired2026-08-31