Azure Private Link Service Configuration for VM Access
You have two Azure subscriptions named Sub1 and Sub2. Sub1 contains a virtual machine named VM1. You plan to make VM1 available to the resources in Sub2 by using Azure Private Link. You need to ensure that the private link service can be configured to provide access to VM1. What should you configure in Sub1 first?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the dependency chain for exposing a VM via Private Link: you must configure a Standard Load Balancer first to create the Private Link Service resource.
This page explains how to expose an Azure Virtual Machine to another subscription using Azure Private Link, focusing on the prerequisite configuration of a Standard Load Balancer. It establishes that a load balancer is required before creating the Private Link Service.
Most learners incorrectly select 'Private Endpoint' (D), confusing the consumer side (subscriber) with the provider side (VM owner). They fail to realize that a VM cannot be directly attached to a Private Endpoint; it needs a frontend IP configuration via a Load Balancer or NAT Gateway.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To make a virtual machine available via Azure Private Link, you must first create a Private Link Service in the provider's subscription (Sub1). A Private Link Service requires a frontend IP configuration, which is provided by an Azure Standard Load Balancer. Therefore, configuring the load balancer is the necessary first step. Without the load balancer, you cannot define the backend pool or the frontend IP that the Private Link Service will expose.Why the Other Options Are Wrong
Option D (Private Endpoint) is incorrect because a private endpoint is created in the consumer subscription (Sub2) to connect to the service; it is not configured in Sub1 first. Option A (Private DNS zone) is typically associated with the consumer side or manual resolution, not the initial infrastructure setup in the provider side. Option C (Service Endpoint) provides access over the Microsoft backbone but does not use Private Link and is not the correct mechanism for this scenario.Community Comment Notes
Community consensus strongly supports Option B. One user noted, "You need to create the load balancer first," citing official documentation. Another commenter clarified the workflow: "Configure 1. Standard LB (Provider side)... Enable private link service." A dissenting vote for D was corrected by noting, "VM is not supported as private endpoint resource," confirming that the VM must go through a load balancer or similar frontend.Official Reference
Exam Strategy
Always distinguish between the 'Provider' (resource owner) and 'Consumer' (access seeker) roles in Private Link questions. If the question asks what to configure in the subscription containing the VM/service, look for the Load Balancer or NAT Gateway required to host the Private Link Service.
Frequently Asked Questions
Why can't I attach the VM directly to a Private Endpoint?
A Private Endpoint connects to a specific Azure service resource. For a VM, you must expose it via a Private Link Service, which requires a Load Balancer frontend IP configuration.
Do I need a Public IP for the Load Balancer?
No, when used with Private Link, the Standard Load Balancer should be configured without a public IP address to ensure traffic remains within the Azure backbone.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →