Skip to main content

Azure Private Endpoint

A network interface that connects privately to an Azure PaaS service (like Storage or SQL Database) using a private IP address from your VNet, eliminating exposure of that service over the public internet.

Azure Private Endpoint

A Private Endpoint gives a PaaS service like a Storage Account or SQL Database a private IP inside your VNet, so traffic to it never traverses the public internet.

Why It Matters in Production

Razorpay's application VMs connect to their production Storage Account exclusively through a Private Endpoint, with public network access disabled entirely on the storage account — eliminating an entire attack surface around exposed storage endpoints.

Bash
az network private-endpoint create --resource-group razorpay-prod-rg \
--name storage-pe --vnet-name razorpay-prod-vnet --subnet pe-subnet \
--private-connection-resource-id <storage-account-id> \
--group-id blob --connection-name storage-connection
Security

After creating a Private Endpoint, explicitly disable public network access on the PaaS resource itself — the endpoint alone doesn't block the public route unless you turn it off.

Frequently Asked Questions

How does a Private Endpoint differ from a Service Endpoint?

A Service Endpoint keeps traffic on the Azure backbone but the PaaS service still has a public IP and firewall rules restricting which VNets can reach it. A Private Endpoint goes further by injecting an actual private IP from your VNet's address space into the PaaS service, so it appears as just another resource on your network with no public endpoint involved at all. This closes off exposure to the internet entirely, not just restricts it, and is required for stricter compliance postures.

What's a common issue teams hit after enabling Private Endpoints?

DNS resolution breaks. Azure PaaS services normally resolve to a public IP, and simply creating the Private Endpoint doesn't rewrite that — you also need a Private DNS Zone linked to the VNet so the service's FQDN resolves to the new private IP instead. Teams that skip this step find the private connection technically exists but clients still route out to the public endpoint (or fail entirely if the public endpoint was disabled), and it looks like the private endpoint 'isn't working' when it's actually a DNS gap.