Private Endpoint UDR Routing Prerequisite

Design and implement Azure Private Link service and Azure private endpoints
Answer Correct answer: A — Enable network policy on Subnet1 to allow the application of User-Defined Routes to the private endpoint.

You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains a subnet named Subnet1. You plan to add a private endpoint to Subnet. You need to ensure that you can route traffic between the private endpoint and the Azure Private Link service by using a user-defined route. What should you do first on Subnet1?

  1. Enable network policy. Correct Answer
  2. Enable delegation.
  3. Create a service endpoint.
  4. Provision a Standard Azure load balancer.

Community Votes

B
50%
A
50%

50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the prerequisite for applying security policies to private endpoints: unlike standard subnets, private endpoints require 'Network Policies' to be enabled rather than delegation or service endpoints.

This question addresses the specific subnet configuration required to apply User-Defined Routes (UDRs) and Network Security Groups to an Azure Private Endpoint. It establishes that network policies must be explicitly enabled on the subnet before the private endpoint is created.

Candidates often select Enable Delegation because it is a common requirement for other Azure services like App Service Environments or Container Instances, but delegation prevents the subnet from being used by Private Endpoints.

Community Discussion (8 comments)

tc0369 👍 1 Selected: A
100% A. https://learn.microsoft.com/en-us/azure/private-link/disable-private-endpoint-network-policy?tabs=network-policy-portal
a250fb0 👍 2 Selected: B
Enabling delegation on Subnet1 allows you to assign the subnet to specific Azure services, such as Azure Private Link. This is necessary for configuring user-defined routes for private endpoints
bobothewiseman 👍 1 Selected: B
Delegation! When creating a private endpoint, Azure needs to control traffic routing between the endpoint and the Azure Private Link service. To do this, the subnet where the private endpoint resides must be delegated to the appropriate Azure service (e.g., Private Link).
manhattan 👍 2 Selected: A
Delegation Can't be used with a private endpoint if the subnet is delegated. https://learn.microsoft.com/en-us/azure/virtual-network/subnet-delegation-overview#effect-of-subnet-delegation-on-your-subnet It's A Enable Network Policy, By default, network policies are disabled for a subnet in a virtual network. To use network policies like user-defined routes and network security group support, network policy support must be enabled for the subnet, This setting only applies to private endpoints in the subnet and affects all private endpoints in the subnet https://learn.microsoft.com/en-us/azure/private-link/disable-private-endpoint-network-policy?tabs=network-policy-portal
rilanc24 👍 1 Selected: A
Can't be used with a private endpoint if the subnet is delegated. https://learn.microsoft.com/en-us/azure/virtual-network/subnet-delegation-overview
gaurav4101 👍 1 Selected: B
Considering Question statement what you do in subnet1 would be enabling delegation to ensure that traffic to and from the private endpoint is correctly routed to the Azure Private Link service
nap61 👍 3 Selected: A
Sorry! Amending! https://learn.microsoft.com/en-us/azure/private-link/private-link-faq#can-i-use-for-user-defined-routes-only--network-security-groups-only--or-for-both-for-private-endpoint- Can I use for User-Defined Routes only, Network Security Groups only, or for both for Private EndPoint? Yes. To utilize policies like User-Defined Routes and Network Security Groups, you need to enable Network policies for a subnet in a virtual network for the Private Endpoint. This setting affects all the private endpoints within the subnet.
nap61 👍 3 Selected: B
To route traffic between the private endpoint and the Azure Private Link service using a user-defined route, you should Enable delegation on Subnet1. So, the correct answer is: B. Enable delegation. Delegation on a subnet is necessary for private endpoints to communicate with Azure Private Link services, as it allows the necessary configuration and management of private endpoints within that subnet.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To route traffic between a private endpoint and the Azure Private Link service using a user-defined route (UDR), you must first enable network policy on the subnet. By default, network policies are disabled for subnets containing private endpoints to allow the underlying infrastructure to manage the endpoint's lifecycle. Enabling this policy allows Azure to enforce UDRs and NSGs on the private endpoint's network interface.

Why the Other Options Are Wrong

Enabling delegation (Option B) assigns control of the subnet to a specific Azure resource provider (like Microsoft.Web or Microsoft.App). A subnet can only have one delegation; if it is delegated to another service, it cannot host a private endpoint. Creating a service endpoint (Option C) exposes resources over the Azure backbone but does not enable UDR support on private endpoints. Provisioning a Standard Load Balancer (Option D) is unrelated to the internal routing requirements of a private endpoint.

Community Comment Notes

Several community members correctly identified that delegation is incompatible with private endpoints. One user noted that "Delegation Can't be used with a private endpoint if the subnet is delegated," citing official documentation. Another learner confirmed that enabling network policy is the necessary step to utilize policies like UDRs, stating "To use network policies like user-defined routes... network policies must be enabled."

Official Reference

Exam Strategy

When dealing with Private Endpoints, always check if the question involves security policies (NSG/UDR). If so, the answer is typically 'Enable Network Policy.' Remember that Private Endpoints do not use Subnet Delegation.

Frequently Asked Questions

Why can't I use delegation for a private endpoint subnet?

Delegation assigns subnet control to a specific Azure service provider. Since Private Endpoints are managed by the Virtual Network infrastructure, they conflict with delegation.

Do I need a load balancer for private endpoint routing?

No. Private endpoints rely on the Azure backbone and UDRs for routing. A load balancer is used for inbound/outbound traffic distribution, not internal endpoint routing.

Related Analysis

Practice All AZ-700 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-700 Practice Test →

← Back to AZ-700 Study Guide