Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planHard

A DevOps team is deploying sensitive APIs to Azure App Service. They need to restrict access to these APIs so that only other authorized Azure services (e.g., Azure Functions, Logic Apps) within their virtual network can call them. External internet access must be blocked. Which networking feature should be configured on the Azure App Service to achieve this?

  1. AService Endpoints or Private Endpoints (Azure Private Link)
  2. BNetwork Security Groups (NSG)
  3. CApplication Gateway with Web Application Firewall (WAF)
  4. DAzure Firewall
Show answer & explanation

Correct answer: A. Service Endpoints or Private Endpoints (Azure Private Link)

Service Endpoints and Private Endpoints (via Azure Private Link) are designed to provide secure and direct connectivity to Azure PaaS services from within your virtual network, bypassing the public internet. For App Service, using Private Endpoints dedicates a private IP address within your VNet to the App Service, ensuring that only resources within that VNet (or connected VNets) can reach it, effectively blocking external internet access while allowing internal Azure services to communicate securely.

Why the other options are wrong

  • B. NSGs filter network traffic to/from Azure resources within a VNet, but App Service itself is a PaaS that typically has a public endpoint. NSGs can't directly block public access to a standard App Service unless it's VNet-integrated with specific configurations, which Private/Service Endpoints simplify.
  • C. Application Gateway with WAF is primarily for inbound web traffic load balancing and security for *publicly accessible* web applications, not for making an App Service exclusively private to a VNet.
  • D. Azure Firewall is a managed, cloud-based network security service that protects your Azure Virtual Network resources. While it can filter outbound traffic or act as a central point for north-south traffic, it's not the primary mechanism to make a PaaS service like App Service *only* accessible privately within a VNet.

Azure Private Link / Private Endpoints for PaaS

A service that enables you to access Azure PaaS services (like App Service, Storage, Key Vault) over a private endpoint in your virtual network, bringing the service into your VNet and removing public internet access.

  • Secures connectivity to PaaS services.
  • Traffic travels over Microsoft's backbone network, not public internet.
  • Enables private IP access for PaaS services, blocking public access.

Memory trick: Private Link 'Brings the Cloud Inside', keeping it off the public 'Street'.

More Develop a security and compliance plan questions