Skill

azure-private-link

Expert knowledge for Azure Private Link development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, and configuration. Use when building, debugging, or optimizing Azure Private Link applications. Not for Azure Virtual Network (use azure-virtual-network), Azure Virtual Network Manager (use azure-virtual-network-manager), Azure VPN Gateway (use azure-vpn-gateway), Azure ExpressRoute (use azure-expressroute).

From azure
Install
1
Run in your terminal
$
npx claudepluginhub atc-net/atc-agentic-toolkit --plugin azure
Tool Access

This skill uses the workspace's default tool permissions.

Skill Content

Azure Private Link Skill

This skill provides expert guidance for Azure Private Link. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, and configuration. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: This file may be large. Use the Category Index below to locate relevant sections, then use read_file with specific line ranges (e.g., L136-L144) to read the sections needed for the user's question This skill requires network access to fetch documentation content. Use mcp_microsoftdocs:microsoft_docs_fetch to retrieve full articles.

  • Fallback: Use the built-in WebFetch tool if the Microsoft Learn MCP server is not available.

Category Index

CategoryLinesDescription
TroubleshootingL35-L40Diagnosing and fixing Azure Private Endpoint and Private Link service connectivity issues, including DNS, network routing, and common misconfiguration problems.
Best PracticesL41-L45DNS design and configuration guidance for private endpoints, including zone setup, name resolution patterns, split-horizon DNS, and avoiding common DNS misconfigurations with Private Link
Decision MakingL46-L51Guidance on planning/migrating to Network Security Perimeter and designing Azure Private Link architectures optimized for security, segmentation, and cost.
Architecture & Design PatternsL52-L56Designing DNS architectures for Private Endpoints using Azure Private Resolver, including name resolution patterns, forwarding rules, and integration with on-premises or hybrid networks
Limits & QuotasL57-L62Regional availability of Private Link/Endpoints, supported services, and how to view or request increases to per‑VNet and global Private Endpoint limits
SecurityL63-L69Configuring RBAC for Private Link/Private Endpoints and Network Security Perimeters, and inspecting/controlling Private Endpoint traffic with Azure Firewall.
ConfigurationL70-L82Configuring Private Link endpoints/services: subnet and NSG policies, ASGs, DNS zones, SNAT bypass, NSPs, and monitoring/diagnostic logs for private connectivity.

Troubleshooting

TopicURL
Diagnose Azure Private Endpoint connectivity issueshttps://learn.microsoft.com/en-us/azure/private-link/troubleshoot-private-endpoint-connectivity
Troubleshoot Azure Private Link service connectivityhttps://learn.microsoft.com/en-us/azure/private-link/troubleshoot-private-link-connectivity

Best Practices

TopicURL
Apply DNS integration best practices for Azure Private Endpointshttps://learn.microsoft.com/en-us/azure/private-link/private-endpoint-dns-integration

Decision Making

TopicURL
Plan and transition Azure resources to Network Security Perimeterhttps://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-transition
Optimize Azure Private Link design for cost and securityhttps://learn.microsoft.com/en-us/azure/private-link/private-link-cost-optimization

Architecture & Design Patterns

TopicURL
Design DNS infrastructure for Private Endpoints with Azure Private Resolverhttps://learn.microsoft.com/en-us/azure/private-link/tutorial-dns-on-premises-private-resolver

Limits & Quotas

TopicURL
Check Azure Private Link regional availability and supporthttps://learn.microsoft.com/en-us/azure/private-link/availability
Increase Azure Private Endpoint per‑VNet and global limitshttps://learn.microsoft.com/en-us/azure/private-link/increase-private-endpoint-vnet-limits

Security

TopicURL
Configure RBAC permissions for Azure Network Security Perimeter operationshttps://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-role-based-access-control-requirements
Assign Azure RBAC roles for Private Endpoint and Private Link deploymenthttps://learn.microsoft.com/en-us/azure/private-link/rbac-permissions
Inspect and control Private Endpoint traffic using Azure Firewallhttps://learn.microsoft.com/en-us/azure/private-link/tutorial-inspect-traffic-azure-firewall

Configuration

TopicURL
Configure application security groups with Azure Private Endpointshttps://learn.microsoft.com/en-us/azure/private-link/configure-asg-private-endpoint
Configure Private Link service Direct Connect destinationshttps://learn.microsoft.com/en-us/azure/private-link/configure-private-link-service-direct-connect
Create a network security perimeter with Azure CLIhttps://learn.microsoft.com/en-us/azure/private-link/create-network-security-perimeter-cli
Configure subnet network policies for private endpointshttps://learn.microsoft.com/en-us/azure/private-link/disable-private-endpoint-network-policy
Disable subnet network policies for Private Link servicehttps://learn.microsoft.com/en-us/azure/private-link/disable-private-link-service-network-policy
Manage Azure private endpoint configuration propertieshttps://learn.microsoft.com/en-us/azure/private-link/manage-private-endpoint
Reference for Azure Private Link monitoring datahttps://learn.microsoft.com/en-us/azure/private-link/monitor-private-link-reference
Enable and store Network Security Perimeter diagnostic logshttps://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-diagnostic-logs
Configure private DNS zone names for Azure Private Endpointshttps://learn.microsoft.com/en-us/azure/private-link/private-endpoint-dns
Enable SNAT bypass for private endpoint traffic via NVAhttps://learn.microsoft.com/en-us/azure/private-link/private-link-disable-snat
Stats
Parent Repo Stars0
Parent Repo Forks1
Last CommitMar 19, 2026