Microsoft Certified: Azure Administrator AssociateDeploy and manage Azure compute resourcesMedium

A company is deploying a new web application to Azure. The application's backend requires access to an on-premises SQL Server instance. The security team mandates that all traffic to on-premises resources must flow through a secure, private connection and not traverse the public internet. You plan to deploy the web application using Azure App Service. Which Azure networking feature should you implement to meet these requirements?

  1. AAzure App Service VNet Integration (Gateway Required)
  2. BAzure Private Link for App Service
  3. CAzure Front Door
  4. DAzure Load Balancer
Show answer & explanation

Correct answer: A. Azure App Service VNet Integration (Gateway Required)

Azure App Service VNet Integration, specifically the gateway-required option, allows your App Service app to access resources in your on-premises network via a VPN Gateway or ExpressRoute connection to an Azure Virtual Network. This ensures private, secure communication as mandated.

Why the other options are wrong

  • B. Azure Private Link is used to access Azure PaaS services (like Azure SQL Database, Azure Storage) privately from your VNet, not primarily for App Service to access on-premises resources.
  • C. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It does not provide private access to on-premises resources.
  • D. Azure Load Balancer distributes incoming network traffic across multiple backend resources. It does not facilitate private connectivity from App Service to on-premises resources.

App Service VNet Integration (Gateway)

Allows Azure App Service to privately access resources within an Azure Virtual Network and, via a gateway, on-premises networks.

  • Enables outbound traffic from App Service to VNet resources.
  • Requires a VNet Gateway (VPN or ExpressRoute) for on-premises access.
  • Ensures secure and private communication.

Memory trick: App Services connect to on-premise like a secure VIP pass through the VNet gate.

More Deploy and manage Azure compute resources questions