Azure File Share Private Endpoint

Handian Sudianto 7,511 Reputation points
2026-10-06T04:05:08.14+00:00

Can we access azure file share using private endpoint ip address or custom dns rather than use record on azure private dns?

Azure Private Link
Azure Private Link

An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.

0 comments No comments

2 answers

Sort by: Newest
  1. Marcin Policht 109.9K Reputation points MVP Volunteer Moderator
    2026-10-06T11:08:43.6166667+00:00

    In short - yep - but there are a few caveats.

    You can use your own custom DNS infrastructure, however, you need to configure your custom DNS so that the storage account's original FQDN resolves to the private endpoint's IP address.

    On your custom DNS server, you can create a forward lookup zone for privatelink.file.core.windows.net and add an A record mapping the storage account name to the private endpoint IP address. Alternatively, you can use conditional forwarders to direct queries for the relevant Azure private-link namespace to an Azure Private DNS Resolver.

    When mounting the share, always use the original FQDN, such as mystorageaccount.file.core.windows.net, rather than the privatelink name. DNS should transparently resolve that original name to the private endpoint IP address. This allows applications and clients to continue using the normal Azure Files endpoint name while the actual network traffic is routed through the private endpoint.

    Although you might be able to establish a basic network connection to the private endpoint IP address, mounting Azure Files directly by IP address is not a documented or supported access pattern and can cause important functionality to fail.

    For identity-based authentication using AD DS or Azure AD Kerberos, the authentication process depends on name resolution and the server's FQDN. Targeting the service by IP address can effectively prevent Kerberos authentication from working correctly.

    IP-based access can also cause SSL/TLS certificate validation problems when using HTTPS-based interfaces such as the FileREST API. The certificate presented by Azure is issued for the Azure Files hostname, such as *.file.core.windows.net, rather than for the private endpoint's IP address. Connecting by IP can therefore result in a certificate name mismatch.

    SMB access should likewise use the server's hostname rather than the private endpoint IP address. The supported approach is to preserve the normal Azure Files FQDN and make DNS resolve that name to the private endpoint address.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    Was this answer helpful?


  2. AI answer

    2026-10-06T04:05:22.42+00:00

    Yes.

    A private endpoint gives the file share a private IP in a virtual network, and clients can access it from that virtual network, peered virtual networks, or connected on-premises networks.

    For name resolution, Azure Files does not require Azure Private DNS specifically. A private DNS zone is created or reused by the standard setup, but custom DNS is supported as long as clients resolve the file share’s original host name to the private endpoint’s private IP address.

    Key points:

    1. Custom DNS is supported
      • Custom DNS infrastructure can be used instead of Azure Private DNS.
      • The requirement is that the file share host name resolves to the private endpoint IP.
    2. Use the original host name when mounting
      • Do not mount by using the privatelink name.
      • Use the file share’s original hostName.
    3. Directly using the private endpoint IP is not the documented access pattern
      • The documented model is DNS-based access using the same host name, which resolves either to the public endpoint or the private endpoint depending on DNS.
      • The guidance provided is to mount using the original host name, not the private IP.
    4. DNS behavior matters
      • In networks using private DNS for the share, the host name resolves to the private endpoint IP.
      • With public DNS, it resolves to the public endpoint instead.

    So the supported approach is:

    • keep using the file share’s original host name,
    • use Azure Private DNS or custom DNS,
    • make sure that name resolves to the private endpoint’s private IP.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.