← cd ~/learn
azureblog.co.uk · cheat sheet
Private endpoint DNS zones
The private DNS zone for each common Azure service, and the rules that make private endpoints resolve properly.
Fits on one A4 page. Checked 8 Oct 2026.
Common private DNS zones
| Service | Sub-resource | Private DNS zone |
|---|---|---|
| Storage | blob | privatelink.blob.core.windows.net |
| Storage | file | privatelink.file.core.windows.net |
| Storage | queue / table | privatelink.queue.core.windows.net / privatelink.table.core.windows.net |
| Storage (Data Lake Gen2) | dfs | privatelink.dfs.core.windows.net |
| Key Vault | vault | privatelink.vaultcore.azure.net |
| Azure SQL Database | sqlServer | privatelink.database.windows.net |
| PostgreSQL flexible server | postgresqlServer | privatelink.postgres.database.azure.com |
| Cosmos DB (NoSQL) | Sql | privatelink.documents.azure.com |
| App Service and Functions | sites | privatelink.azurewebsites.net |
| Container Registry | registry | privatelink.azurecr.io |
| Event Hubs and Service Bus | namespace | privatelink.servicebus.windows.net |
| Azure OpenAI and AI services | account | privatelink.openai.azure.com, privatelink.cognitiveservices.azure.com, privatelink.services.ai.azure.com (each endpoint the workload uses) |
| Azure Monitor (private link scope) | azuremonitor | privatelink.monitor.azure.com, privatelink.oms.opinsights.azure.com, privatelink.ods.opinsights.azure.com, privatelink.agentsvc.azure-automation.net, plus privatelink.blob.core.windows.net for agent solution packs |
How resolution works
- Client asks for
stdata.blob.core.windows.net. - Public DNS returns a CNAME to
stdata.privatelink.blob.core.windows.net. - Inside your network, the private DNS zone answers that name with the private IP.
- Everywhere else, the same name resolves to the public endpoint.
Rules that prevent most problems
- One zone per service type, shared across the estate
- Link zones to the VNet where your DNS servers or resolver live
- Custom DNS servers in Azure forward to 168.63.129.16
- On-premises: conditional forwarders for the public domain (blob.core.windows.net) to a Private Resolver inbound endpoint
- Don't host privatelink zones on-premises: accounts without a record there stop resolving
- Create records automatically with Azure Policy
Testing
nslookup stdata.blob.core.windows.net
Resolve-DnsName stdata.blob.core.windows.net | Format-Table Name, Type, IPAddress, NameHost
A private IP means DNS is right. A public IP through the privatelink CNAME means the client can't see the private zone. Full walkthrough: Private endpoints and DNS.