Configuring Azure Private Link for Blob Storage
Pluralsight Hands-On Lab — Storage
At a Glance
| Platform | Pluralsight |
| Category | Azure Storage & Networking |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Linux VM via SSH, Windows VM via Remote Desktop |
| Completed | 2026 |
Overview
Azure Private Link allows Azure Storage to be accessed over a private endpoint within a virtual network, removing exposure to the public internet. These two Pluralsight labs both cover the same core workflow: disabling or restricting public access to a storage account, creating a private endpoint scoped to the blob service, integrating with a private DNS zone, and verifying that the storage account hostname resolves to a private IP address from within the virtual network — confirming all traffic stays off the public internet.
What I Did
- Reviewed the storage account's network settings and confirmed public access was enabled; noted the virtual network subnets (vm-subnet and private-endpoint-subnet)
- Connected to the lab VM via SSH and ran nslookup against the blob endpoint FQDN, confirming it resolved to a public IP address before any changes
- Disabled public network access on the storage account, removing all public internet access to blob storage
- Created a private endpoint (pe-blob-storage / pe-1) scoped to the blob sub-resource of the storage account, placed in the designated private endpoint subnet of the virtual network
- Enabled private DNS zone integration during endpoint creation, provisioning the privatelink.blob.core.windows.net zone and linking it to the virtual network
- Reviewed the private DNS zone record set confirming the storage account name resolved to a private IP in the subnet range
- Confirmed the virtual network link was in place, allowing VMs on the network to resolve the storage account via the private DNS zone
- Re-ran nslookup from the VM and confirmed the blob endpoint FQDN now resolved to a private IP address, verifying all traffic travels within the virtual network
- In a second lab variant, connected to a Windows VM via RDP, ran nslookup from the command prompt against the blob FQDN, and confirmed a private IP (e.g. 10.1.1.5) was returned — validating private endpoint connectivity from a Windows guest
← Back to Pluralsight Labs