Microsoft Certified: Azure Administrator AssociateDeploy and manage Azure compute resourcesMedium

A company is deploying a new web application to Azure App Service. The application needs to connect to an Azure SQL Database instance using a private endpoint. The security team insists that all outbound connections from the App Service to the database must be routed through the virtual network to ensure network isolation and security. Which App Service networking feature should you configure?

  1. AHybrid Connections
  2. BPrivate Link for App Service
  3. CVNet Integration (Regional)
  4. DApp Service Environment (ASE)
Show answer & explanation

Correct answer: C. VNet Integration (Regional)

Regional VNet Integration allows your App Service app to make outbound calls to resources within your virtual network, including private endpoints for Azure SQL Database, ensuring that all traffic flows through the VNet for network isolation.

Why the other options are wrong

  • A. Hybrid Connections are primarily used for connecting App Service to on-premises resources over a secure tunnel, not for accessing Azure PaaS private endpoints within a VNet.
  • B. Private Link for App Service is used to make the App Service itself accessible privately from a VNet, not for the App Service to access resources privately within a VNet.
  • D. App Service Environment (ASE) provides full VNet isolation but is a much more complex and expensive deployment for this specific requirement.

App Service VNet Integration (Regional)

Enables an App Service app to access resources within a Virtual Network in the same region, routing outbound traffic through the VNet.

  • Used for outbound connectivity from App Service to VNet resources.
  • Ensures network isolation for PaaS services with Private Endpoints.
  • Simpler and more cost-effective than App Service Environment for many scenarios.

Memory trick: To send App Service secrets out through the VNet, integrate it regionally.

More Deploy and manage Azure compute resources questions