azureblog.co.uk
← cd ~/learn
azureblog.co.uk · cheat sheet

Private endpoint DNS zones

The private DNS zone for each common Azure service, and the rules that make private endpoints resolve properly.

Fits on one A4 page. Checked 8 Oct 2026.

Common private DNS zones

ServiceSub-resourcePrivate DNS zone
Storageblobprivatelink.blob.core.windows.net
Storagefileprivatelink.file.core.windows.net
Storagequeue / tableprivatelink.queue.core.windows.net / privatelink.table.core.windows.net
Storage (Data Lake Gen2)dfsprivatelink.dfs.core.windows.net
Key Vaultvaultprivatelink.vaultcore.azure.net
Azure SQL DatabasesqlServerprivatelink.database.windows.net
PostgreSQL flexible serverpostgresqlServerprivatelink.postgres.database.azure.com
Cosmos DB (NoSQL)Sqlprivatelink.documents.azure.com
App Service and Functionssitesprivatelink.azurewebsites.net
Container Registryregistryprivatelink.azurecr.io
Event Hubs and Service Busnamespaceprivatelink.servicebus.windows.net
Azure OpenAI and AI servicesaccountprivatelink.openai.azure.com, privatelink.cognitiveservices.azure.com, privatelink.services.ai.azure.com (each endpoint the workload uses)
Azure Monitor (private link scope)azuremonitorprivatelink.monitor.azure.com, privatelink.oms.opinsights.azure.com, privatelink.ods.opinsights.azure.com, privatelink.agentsvc.azure-automation.net, plus privatelink.blob.core.windows.net for agent solution packs

How resolution works

  1. Client asks for stdata.blob.core.windows.net.
  2. Public DNS returns a CNAME to stdata.privatelink.blob.core.windows.net.
  3. Inside your network, the private DNS zone answers that name with the private IP.
  4. Everywhere else, the same name resolves to the public endpoint.

Rules that prevent most problems

  • One zone per service type, shared across the estate
  • Link zones to the VNet where your DNS servers or resolver live
  • Custom DNS servers in Azure forward to 168.63.129.16
  • On-premises: conditional forwarders for the public domain (blob.core.windows.net) to a Private Resolver inbound endpoint
  • Don't host privatelink zones on-premises: accounts without a record there stop resolving
  • Create records automatically with Azure Policy

Testing

nslookup stdata.blob.core.windows.net
Resolve-DnsName stdata.blob.core.windows.net | Format-Table Name, Type, IPAddress, NameHost

A private IP means DNS is right. A public IP through the privatelink CNAME means the client can't see the private zone. Full walkthrough: Private endpoints and DNS.