Deploy a Secure Web App Using NSGs and Private Endpoints

Pluralsight Hands-On Lab — Azure Networking & Security

Deploy a Secure Web App Using NSGs and Private Endpoints

Pluralsight Hands-On Lab — Security


At a Glance

PlatformPluralsight
CategoryAzure Networking & Security
Lab TypeGuided + Challenge Mode
EnvironmentAzure Portal, Linux VM via SSH, Azure CLI
Completed2026

Overview

This lab demonstrates a least-privilege network architecture for Azure PaaS services: public access disabled on both App Service and Blob Storage, Private Endpoints providing inbound connectivity over the virtual network, and an NSG outbound rule restricting VM access to storage at the network layer. I deployed an Azure Web App and Storage account with Private Link, validated private connectivity from a VM using curl and Azure CLI, then enforced selective egress blocking with an NSG rule and confirmed the restriction took effect.


What I Did


← Back to Pluralsight Labs