Private Endpoint: Secure Azure Storage Access Without Public Endpoint
A company has an Azure Storage account that stores application files in Blob Storage. VMs in AppSubnet must access the blobs by using the standard storage account name, but traffic must stay private and the public endpoint must not be used. Which two actions should the administrator take? Select two.
Quick Answer
The correct answer is to create a private endpoint for the storage account and link a private DNS zone for privatelink.blob.core.windows.net to the VNet. A private endpoint assigns the blob service a private IP address from the AppSubnet, enabling VMs to resolve the standard storage account name (e.g., mystorageaccount.blob.core.windows.net) to that internal IP, keeping all traffic within the Azure backbone and completely bypassing the public endpoint. This directly meets the requirement for private traffic without using the public endpoint. On the AZ-104 exam, this scenario tests your understanding of the key difference between Azure Storage private endpoint vs service endpoint: a service endpoint still uses the public endpoint’s FQDN and relies on network policies, while a private endpoint eliminates public exposure entirely. A common trap is choosing a service endpoint because it also keeps traffic on the backbone, but it does not remove the public endpoint. Memory tip: think “Private = Private IP, no public path; Service = Service tag, still public FQDN.”
⚠ Common exam trap
Watch out — candidates often confuse service endpoints with private endpoints, assuming both provide the same level of privacy, but service endpoints still use the public endpoint for the data plane while private endpoints provide a fully private IP address and eliminate public internet exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a private endpoint for the blob service in AppSubnet.
Option A is correct because creating a private endpoint for the blob service in AppSubnet assigns a private IP from the subnet to the storage account's blob service, so VMs reach the blob data over the Azure private backbone rather than the public endpoint. Option C is correct because the standard storage account name (e.g., contoso.blob.core.windows.net) must resolve to the private endpoint's private IP; linking the privatelink.blob.core.windows.net private DNS zone to the VNet creates the required CNAME/A record mapping. Together, the private endpoint plus the privatelink DNS zone let VMs use the normal storage account name while keeping traffic private and avoiding the public endpoint. Option B is incorrect because a service endpoint still routes traffic to the storage account's public IP address over the Azure backbone, so the public endpoint is still used. Option D is incorrect because a shared access signature is an authorization token, not a private network path, and does not prevent public endpoint usage. Option E is incorrect because keeping the public endpoint open and relying on virtual network rules does not satisfy the requirement that the public endpoint must not be used.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a private endpoint for the blob service in AppSubnet.
Why this is correct
A private endpoint places a network interface for the blob service inside AppSubnet, giving the VMs a private IP path and removing reliance on the public endpoint. This satisfies the requirement that traffic stays private while the standard storage account name still resolves.
- ✗
Enable a service endpoint for Microsoft.Storage on AppSubnet.
Why it's wrong here
A service endpoint keeps traffic on the Azure backbone but the storage account still resolves to its public IP address, so the public endpoint remains in use. Service endpoints suit restricting storage access to specific subnets while retaining the public endpoint.
When this WOULD be correct
If the requirement were to restrict access to the storage account from a specific subnet while still allowing traffic over the public endpoint (e.g., for compliance or cost reasons), enabling a service endpoint on AppSubnet and adding a virtual network rule would be correct.
- ✓
Link a private DNS zone for privatelink.blob.core.windows.net to the VNet.
Why this is correct
Linking the privatelink.blob.core.windows.net private DNS zone to the VNet makes the standard storage account name resolve to the private endpoint's IP. Without this zone link, name resolution would return the public address, defeating the private-only requirement.
- ✗
Generate a shared access signature and email it to the VMs.
Why it's wrong here
A SAS token only authorises access; it does not alter the network path, so traffic still traverses the public blob endpoint. SAS is designed for delegated, time-limited access to storage resources, and would suit granting a partner temporary read access without sharing account keys.
When this WOULD be correct
If the question required granting time-limited access to specific blobs for external users without Microsoft Entra ID credentials, and the public endpoint is allowed, a SAS would be correct.
- ✗
Add a virtual network rule to the storage account and keep the public endpoint open.
Why it's wrong here
Keeping the public endpoint open leaves the storage account reachable over the internet, contradicting the requirement that traffic stay private and the public endpoint not be used. It is tempting because virtual network rules do restrict access to specified subnets, and would be correct when public access must remain available alongside subnet-based filtering.
When this WOULD be correct
If the question required restricting access to a specific subnet while still allowing access via the public endpoint (e.g., for hybrid scenarios where on-premises clients need to use the public endpoint), then adding a virtual network rule and keeping the public endpoint open would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Create a private endpoint for the blob service in AppSubnet.Correct answer▾
Why this is correct
A private endpoint places a network interface for the blob service inside AppSubnet, giving the VMs a private IP path and removing reliance on the public endpoint. This satisfies the requirement that traffic stays private while the standard storage account name still resolves.
✗Enable a service endpoint for Microsoft.Storage on AppSubnet.Wrong answer — click to see why▾
Why this is wrong here
A service endpoint does not keep traffic private; it still uses the public endpoint of the storage account, only with source IP filtering. The question requires that the public endpoint not be used.
★ When this WOULD be the correct answer
If the requirement were to restrict access to the storage account from a specific subnet while still allowing traffic over the public endpoint (e.g., for compliance or cost reasons), enabling a service endpoint on AppSubnet and adding a virtual network rule would be correct.
Why candidates choose this
Candidates often confuse service endpoints with private endpoints, thinking both provide private connectivity, but service endpoints do not remove public exposure.
✗Generate a shared access signature and email it to the VMs.Wrong answer — click to see why▾
Why this is wrong here
A shared access signature (SAS) uses the public endpoint, which violates the requirement that traffic must stay private and the public endpoint must not be used.
★ When this WOULD be the correct answer
If the question required granting time-limited access to specific blobs for external users without Microsoft Entra ID credentials, and the public endpoint is allowed, a SAS would be correct.
Why candidates choose this
Candidates may think SAS is a secure way to access blobs without realizing it still uses the public endpoint, or they may confuse SAS with private access methods.
✗Add a virtual network rule to the storage account and keep the public endpoint open.Wrong answer — click to see why▾
Why this is wrong here
Keeping the public endpoint open violates the requirement that the public endpoint must not be used. A virtual network rule alone does not block public access; it only restricts access to traffic from the specified subnet, but the public endpoint remains accessible.
★ When this WOULD be the correct answer
If the question required restricting access to a specific subnet while still allowing access via the public endpoint (e.g., for hybrid scenarios where on-premises clients need to use the public endpoint), then adding a virtual network rule and keeping the public endpoint open would be correct.
Why candidates choose this
Candidates may confuse service endpoints with private endpoints, thinking that a virtual network rule alone ensures private connectivity, but they overlook the requirement to disable public endpoint access.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Azure Blob Storage Access Tiers
Key term
Virtual network
A virtual network is a software-based network that connects computers, servers, and devices over the internet or within a cloud environment, simulating a physical network without requiring dedicated hardware.
Key term
Shared access signature
A shared access signature (SAS) is a secure, time-limited URL that grants granular access to specific resources in cloud storage, allowing you to delegate permissions without sharing your account keys.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,053 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-104
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An application runs in a subnet and must reach a storage account over the public endpoint, but only that subnet should be allowed. The team does not want to use a private endpoint. Which two configurations should the administrator use? Select two.
easy- ✓ A.Enable the Microsoft.Storage service endpoint on the subnet.
- ✓ B.Add the subnet to the storage account's virtual network rules.
- C.Create a private endpoint for the storage account.
- D.Assign the Reader role to the subnet.
- E.Turn on blob soft delete.
Why A: Enabling the Microsoft.Storage service endpoint on the subnet (A) ensures that traffic from the subnet to the storage account's public endpoint is routed through the Azure backbone network and uses the source IP of the subnet's virtual network, allowing the storage account firewall to identify the traffic. Adding the subnet to the storage account's virtual network rules (B) then explicitly permits only that subnet's traffic, denying all other public endpoint access. Together, these two configurations restrict access to the storage account's public endpoint exclusively to the specified subnet without requiring a private endpoint.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.