TECHRUNBOOK · PRACTICAL GUIDE

Azure Private Endpoint Connectivity Troubleshooting Runbook

Troubleshoot Azure Private Endpoint connectivity failures by validating DNS, approval state, routing, NSGs, firewalls and end-to-end reachability.

Practical RunbookTechnical Troubleshooting
Practical Runbook10 StepsIssues → Solutions → Recommendations
Have a question about this runbook?Post your issue to the TechRunbook Community and get help from other IT professionals.
Ask the Community →
!Issue

Troubleshoot Azure Private Endpoint connectivity failures by validating DNS, approval state, routing, NSGs, firewalls and end-to-end reachability.

Solution

Start with Check DNS resolution and work through the six diagnostic checks in order.

Recommendations

Record results before changing configuration and validate the original symptom after each controlled change.

TechRunbook approach: Test one dependency at a time, record the result and only then change the configuration.

Quick checks

Start with the basic checks in this runbook before moving to deeper troubleshooting.

  • Confirm the affected service or component is available.
  • Check recent configuration or connectivity changes.
  • Run the relevant commands and compare the result with the expected state.
01

Check DNS resolution

Resolve the service FQDN and confirm it returns the expected private endpoint address rather than a public address.

02

Check private endpoint state

Confirm the private endpoint connection is approved and provisioning has completed successfully.

03

Check routing

Review effective routes, VNet peering and any Azure Firewall or NVA path between the source and private endpoint subnet.

04

Check network security

Check subnet and NIC NSGs and security appliances for rules affecting the required destination port.

05

Test private IP connectivity

Test the private endpoint IP from the affected source network to separate DNS problems from network problems.

06

Validate application access

Retest the application path and confirm the workload is using the intended private connectivity path.

07

Useful commands

Run these checks from an appropriate administrative session and replace example values with your environment.

DNS resolution

Resolve-DnsName <service-fqdn>

TCP reachability

Test-NetConnection <private-ip> -Port <port>
08

Quick troubleshooting path

Use this sequence to isolate the failing dependency before changing production configuration.

  1. Check DNS resolution → Resolve the service FQDN and confirm it returns the expected private endpoint address rather than a public address.
  2. Check private endpoint state → Confirm the private endpoint connection is approved and provisioning has completed successfully.
  3. Check routing → Review effective routes, VNet peering and any Azure Firewall or NVA path between the source and private endpoint subnet.
  4. Check network security → Check subnet and NIC NSGs and security appliances for rules affecting the required destination port.
  5. Test private IP connectivity → Test the private endpoint IP from the affected source network to separate DNS problems from network problems.
  6. Validate application access → Retest the application path and confirm the workload is using the intended private connectivity path.
09

What good troubleshooting looks like

Good infrastructure troubleshooting is evidence-driven. Capture the original state, test the dependency that can prove or disprove your hypothesis, make the smallest safe change and repeat the original test.

Example workflow
Symptom → hypothesis → direct test → result → controlled change → validation → documentation
10

Frequently asked questions

What should I check first?

Start with the exact symptom and validate the dependency closest to the failure in this Azure runbook.

Should I change production configuration immediately?

No. Capture the current state first, test the suspected dependency and make one controlled change at a time.

How should I document the fix?

Record the symptom, commands used, result, configuration change and validation result so the procedure can be repeated.

+

Related TechRunbook guides

Was this runbook helpful?

↑ Top