Deploy a Secure Web App Using NSGs and Private Endpoints
Pluralsight Hands-On Lab — Security
At a Glance
| Platform | Pluralsight |
| Category | Azure Networking & Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Linux VM via SSH, Azure CLI |
| Completed | 2026 |
Overview
This lab demonstrates a least-privilege network architecture for Azure PaaS services: public access disabled on both App Service and Blob Storage, Private Endpoints providing inbound connectivity over the virtual network, and an NSG outbound rule restricting VM access to storage at the network layer. I deployed an Azure Web App and Storage account with Private Link, validated private connectivity from a VM using curl and Azure CLI, then enforced selective egress blocking with an NSG rule and confirmed the restriction took effect.
What I Did
- Deployed an Azure App Service (Web App) with public access disabled, virtual network integration enabled, and a private endpoint (webappprivateendpoint) placed in the privatelink subnet — confirmed public access returned HTTP 403 Forbidden
- Deployed an Azure Storage account with public network access disabled and a private endpoint (storageprivateendpoint) in the same privatelink subnet, scoped to Blob storage
- Connected to the lab VM via SSH from the Instant Terminal and ran curl against the Web App's default domain, receiving the App Service welcome HTML — confirming private connectivity worked while public access remained blocked
- Authenticated to Azure CLI from the VM using device code flow and ran az storage blob list against the $logs container, receiving an empty result [] — confirming private connectivity to Storage over Private Link
- Retrieved the private endpoint IP for the Storage account from the privatelink.blob.core.windows.net private DNS zone recordset
- Added an outbound NSG rule (block-storage) on the VM's NSG targeting the Storage private endpoint IP on HTTPS with action Deny
- Re-ran the blob list command after propagation and confirmed the command hung and timed out without returning [], validating the NSG was blocking the VM's outbound access to Storage on port 443
← Back to Pluralsight Labs