More info about Internet Explorer and Microsoft Edge, connect Azure Front Door Premium to a App Service origin with Private Link, connect Azure Front Door Premium to a storage account origin with Private Link, connect Azure Front Door Premium to an internal load balancer origin with Private Link. The access modes set on the AMPLS resource affect all networks, but you can override these settings for specific networks. For more information, see Use Azure Private Link to securely connect networks to Azure Automation. AMPLS B is connected to Private Endpoints of two VNets (VNet2 and VNet3), using two of the 10 possible Private Endpoint connections. For this scenario, assume you want to disable all public access to your logical server and allow connections only from your virtual network. The platform validates network connections, allowing only those that reach the specified private-link resource. Azure Private Link enables you to access Azure PaaS services and services hosted in Azure over a private endpoint in your virtual network. The following services may require all destination ports to be open when leveraging a private endpoint and adding NSG security filters: More info about Internet Explorer and Microsoft Edge, Manage network policies for private endpoints, Configure an application security group (ASG) with a private endpoint, Quickstart: Create a private endpoint by using the Azure portal, The subnet to deploy, where the private IP address is assigned. The simplest and most secure approach would be: If you can't add all Azure Monitor resources to your AMPLS, you can still apply your Private Link to some resources, as explained in Control how Private Links apply to your networks. So it doesn't require private endpoints for backup and restore. A read-only property that specifies whether the private endpoint is active. Any login attempts made directly to the IP address or using the private link FQDN (