Skip to the main content.
Cubesys
Cubesys
  • Services
    • Cloud Managed Services
    • Cloud Adoption, Automation & Optimisation
    • Modern Workplace
    • Azure Virtual Desktop (AVD)
    • Windows 365
    • Disaster Recovery
    • Surface Modern Solutions
  • Solutions
    • Our Solutions
    • Virtual Desktop – Economic Plan for Success
    • ISV Assist
    • Cloud Governance
    • Cyber Aware
    • Microsoft 365 Economic Plan
    • Virtual Desktop Deployment Services
    • Azure Migration Economic Plan
    • Azure Optimisation with CloudClarity
    • Azure Ready and Govern Foundations
  • Support
  • About
    • About cubesys
    • Our Team
    • Our Partners
  • Latest
    • Blog
    • Events
  • Case Studies
  • Careers
  • Contact
1300 043 176
1300 043 176
  • Services
    • Cloud Managed Services
    • Cloud Adoption, Automation & Optimisation
    • Modern Workplace
    • Azure Virtual Desktop (AVD)
    • Windows 365
    • Disaster Recovery
    • Surface Modern Solutions
  • Solutions
    • Our Solutions
    • Virtual Desktop – Economic Plan for Success
    • ISV Assist
    • Cloud Governance
    • Cyber Aware
    • Microsoft 365 Economic Plan
    • Virtual Desktop Deployment Services
    • Azure Migration Economic Plan
    • Azure Optimisation with CloudClarity
    • Azure Ready and Govern Foundations
  • Support
  • About
    • About cubesys
    • Our Team
    • Our Partners
  • Latest
    • Blog
    • Events
  • Case Studies
  • Careers
  • Contact

2 min read

Azure Private Link has been added to Azure Monitor

cubesys : Jun 2, 2022 12:00:00 AM

Azure
Azure Private Link has been added to Azure Monitor

Private links – What are they? Why do you need them? How do you implement them? 

Keeping your environment secure is important, even in the cloud. Some organisations or environments required private and secure communication even for their monitoring solutions, Azure Private Link has recently been enabled for Azure Monitor 

Because public networks are just that – public. They are open to anyone who wishes to use them and as such, any communication passing through them is potentially visible to anyone who cares to look (also known as man in the middle).  

As an organisation, this is a big security concern. We’ve all heard the horror stories of companies that have had their confidential data compromised by hackers who were able to gain access to their networks through open/unprotected Wi-Fi networks. It’s a costly mistake and PR nightmare for any brand, which is why you need to take extra steps to protect your organisation’s data, even the monitoring data. 

Today, we’ll discuss private links and how to set them up using a Domain Name System (DNS). By the end of this article, you’ll know how to create a private link and use it with Azure Monitor. Let’s explore  

What are private links?  

This is where private links come in. Private links work by setting up a private endpoint within your internal DNS environment. 

Traffic between your network and the service using internal IP addressing and travels the Microsoft backbone network. This eliminates the requirement to expose service to the public internet. You can create your own private link service in your Azure virtual network and deliver it to your customers. Setup and consumption using Azure Private Link is consistent across Azure PaaS, customer-owned services. 

Setup Azure Monitor private link 

Azure Monitor is a great solution for monitoring your cloud environment, but it can be difficult to keep your data secure when you’re using it.  

One of the best ways to keep your data safe is to use a private link between your Azure Monitor environment and your on-premises environment. This will prevent traffic from passing between your environment and the Azure Monitoring platform through the public network. 

From the Azure Portal, go to Azure Monitor: 

  1. Within the settings section select “Private Link Scopes” 
  2. Click Create 
  3. Provide your subscription, resource group and instance detail, and select Private Only
Accessing Private Link Scopes blade in Azure Monitor
Step 2
Azure Monitor Private Link Scope creation process and settings.
Step 3

For the initial setup, it’s recommended to leave it as open. Once you’ve reconfigured all your endpoints to use the private endpoint, then finally come back to your AMPLS and select Private Only.

Implementing a private link into your DNS

We’ll now focus on implementing Private Link and integrating it within Active Directory DNS Servers that are on-prem. Implementing this in Azure DNS can be done by just completing step 2.

To get the name resolution working, you’ll need the following:

  • DNS Server on-prem
  • DNS Server within Azure Virtual Network (This will soon be replaced by DNS Private Resolver which is now in Public Preview)
  1. Create a conditional forwarder within DNS server for privatelink.monitor.azure.com and point those towards your Azure VM, which is a DNS relay in cloud.
  2. On your Azure VM DNS server, configure its DNS forwarders to Azure’s public DNS services IP 168.63.129.16.
Preview of private link DNS domain and IP address.

Private links are a great way to keep your data safe and secure, and using DNS is one of the best ways to set them up. In this article, we’ve shown you how to create a private link using DNS and how to use it securely with Azure Monitor. 

By following the steps in this guide, you’ll be well on your way to implementing a private link into your network. Ready to get started with Azure? Check out our services here. 

  • Tweet
Understanding Azure DNS Private Resolver

Understanding Azure DNS Private Resolver

cubesys : Jul 1, 2022 12:00:00 AM

Another new service introduced this year so far by Microsoft, Azure DNS (Domain Name System) Private Resolver is a cloud-native, DevOps-friendly,...

Azure
Read More

Microsoft Azure Networking Certification

cubesys : Jul 27, 2021 12:00:00 AM

Whilst I know that many people have been looking forward to a Azure Networking certification for some time, this doesn’t mean it comes easy! There is...

Microsoft Learn Azure
Read More

Azure – You can now use FQDN name to define your Local Network Gateway

cubesys : Oct 22, 2020 12:00:00 AM

As you know, you can setup a Site-to-Site VPN between your on-premises infrastructure and Azure.

Azure Security
Read More
CBD Office

Suite 221
111 Harrington Street,
The Rocks NSW 2000,
Australia

ABN 39 163 878 859

Phone 1300 163 712

Contacts

Support 1300 043 176

info@cubesys.com.au

sales@cubesys.com.au

Solutions
  • Modern Workplace
  • Cloud Adoption, Automation & Optimisation
  • Disaster Recovery
  • Support Services
Cubesys
  • Privacy Policy
  • Terms of Use

© 2025 cubesys

X Linkedin YouTube