An AI engineering team is developing a highly sensitive document processing solution using Azure AI services. They need to ensure that the AI services can only be accessed from specific, authorized virtual networks within their Azure subscription. Additionally, all traffic to these services must traverse the Azure backbone network and not the public internet. Which two Azure networking features should the team implement?
- AAzure Private Link and Network Security Groups (NSGs).
- BAzure Private Link and Azure Firewall.
- CAzure Private Link and Virtual Network (VNet) Service Endpoints.
- DAzure Front Door and Network Security Groups (NSGs).
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Private Link and Network Security Groups (NSGs).
Azure Private Link, through Private Endpoints, ensures that traffic to the AI services traverses the Azure backbone network privately and is not exposed to the public internet, meeting the requirement for private backbone traffic. Network Security Groups (NSGs) can then be used within the virtual network to control inbound and outbound traffic to and from the subnets where the client applications or Private Endpoints reside, ensuring access only from 'specific, authorized virtual networks' by filtering based on IP addresses or service tags.
Why the other options are wrong
- B. Azure Private Link (with Private Endpoints) handles the private connectivity. Azure Firewall is a centralized network firewall that can filter traffic, but NSGs are more commonly used for granular control within a VNet at the subnet level to restrict access to the Private Endpoint itself.
- C. VNet Service Endpoints allow VNet traffic to reach Azure services over an optimized route but still use public IP addresses for the service, failing the 'not the public internet' requirement. Azure Private Link provides true private connectivity.
- D. Azure Front Door is a global load balancer and WAF, not for privatizing access to backend services within a VNet. NSGs are for network filtering but don't privatize the service connection.
Azure Private Link & NSG for AI Security
Azure Private Link (via Private Endpoints) enables private, backbone-only access to Azure AI services from within a VNet. Network Security Groups (NSGs) then provide granular filtering of traffic within the VNet to control which resources can access these Private Endpoints.
- Private Link ensures traffic stays on Azure backbone.
- Private Link provides a private IP for the service in your VNet.
- NSGs filter traffic at the subnet or NIC level.
- Combined, they offer strong network isolation and access control.
Memory trick: Private Link is the private 'road', NSGs are the 'checkpoints' on that road.