Why does a VM still resolve a storage account publicly after a private endpoint was added?
Editorial worked example. The participant profiles, discussion timeline and activity counts are illustrative; they are not a record of a customer incident. Scenario date: Mar 5, 2022. Technical guidance is based on the linked sources and was prepared for this publication.
25 reputation · 1h ago
AI-assisted content · Sources linked below.
A storage private endpoint and its DNS record exist. A VM in a connected network still resolves the ordinary blob hostname to a public address. The VM uses a custom DNS server, while another VM using the intended Azure resolver gets a private address. The application configuration has not changed. Which part of the DNS chain should be investigated?
25 reputation · 1h ago
The DNS server has cached the public answer. Should I delete the private zone and recreate it?
1,450 reputation · 1h ago
No. Confirm the forwarding configuration first and account for the cached record TTL. Recreating a correct zone adds disruption without addressing the resolver that supplied the answer.