An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
Yes.
A private endpoint gives the file share a private IP in a virtual network, and clients can access it from that virtual network, peered virtual networks, or connected on-premises networks.
For name resolution, Azure Files does not require Azure Private DNS specifically. A private DNS zone is created or reused by the standard setup, but custom DNS is supported as long as clients resolve the file share’s original host name to the private endpoint’s private IP address.
Key points:
- Custom DNS is supported
- Custom DNS infrastructure can be used instead of Azure Private DNS.
- The requirement is that the file share host name resolves to the private endpoint IP.
- Use the original host name when mounting
- Do not mount by using the
privatelinkname. - Use the file share’s original
hostName.
- Do not mount by using the
- Directly using the private endpoint IP is not the documented access pattern
- The documented model is DNS-based access using the same host name, which resolves either to the public endpoint or the private endpoint depending on DNS.
- The guidance provided is to mount using the original host name, not the private IP.
- DNS behavior matters
- In networks using private DNS for the share, the host name resolves to the private endpoint IP.
- With public DNS, it resolves to the public endpoint instead.
So the supported approach is:
- keep using the file share’s original host name,
- use Azure Private DNS or custom DNS,
- make sure that name resolves to the private endpoint’s private IP.