Understand the concept
Azure Virtual Machines support guest-machine management. App Service offers managed application hosting; Azure Functions supports event-driven execution. Containers add packaging portability, but runtime platform and operations remain choices. Consider duration, dependencies, load, and team capability when selecting.
Apply and decide
VNets and subnets organize virtual networks. Peering connects networks under supported rules; VPN Gateway and ExpressRoute address hybrid connectivity with different characteristics. Private endpoints provide private access to supported services but do not replace authorization or DNS configuration. For a failed connection, separate resolution, routing, transport, and identity.
Workplace application
In a fictional banking batch, the client still resolves a public endpoint after a private endpoint is created. Compare resolution at the affected origin, routing, and permissions without granting administrative access in an attempt to fix DNS. For application hosting, distinguish VM control, managed platforms, and event-driven execution. A service name does not remove the need to assess dependencies, limits, operations, and the identity used by code.
After a private endpoint is created, the client still resolves the public address. Validate DNS and network paths before concluding identity failed.
Common pitfalls
Using broad permissions to try to fix DNS and connectivity.
Related topics: Storage, retention, and recovery · Identity, access, and governance
Compute selection and private access need operational validation.
Reference: Azure Private Endpoint DNS · AZ-900 skills measured July 20, 2026