Session

Private Link & Private Endpoints: Eliminating Public Exposure for PaaS Services

It's a familiar story: a misconfigured storage account or database left with a public endpoint becomes the entry point for a breach. Private Link and Private Endpoints solve this problem by bringing PaaS services directly into your virtual network — but getting DNS resolution right is where most implementations go wrong.

This session walks through the full architecture of Private Endpoints, including how they attach as NICs within a subnet and how traffic is routed privately without ever touching the public internet. The core of the session is dedicated to Private DNS Zone design — how resolution works in single-VNet scenarios, how it changes in hub-spoke topologies, and how to extend private resolution to on-premises networks via conditional forwarders. We'll also address more advanced scenarios: cross-subscription and cross-tenant Private Link connections, and how to handle Private Endpoints in multi-tenant SaaS architectures.

The session includes a live demo locking down an Azure SQL Database and Storage Account — removing public network access entirely and validating connectivity end-to-end. Attendees will leave with a repeatable pattern for auditing and remediating public PaaS exposure across their subscriptions.

Santhoshkumar Anandakrishnan

Lead Cloud Architect

Melbourne, Australia

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top