Private endpoints
Private endpoints enable further integration between Azure PaaS services and VNet. Whereas service endpoints allow secure communication between PaaS and IaaS, private endpoints fully integrate PaaS to VNet. Service endpoints allow communication over the Microsoft backbone network, but PaaS services are still available over the internet. Private endpoint integrates service to VNet, after which a service is assigned a private IP address and all communications are done over a private network (VNet).
Using private endpoints, PaaS workloads can be accessed exclusively over a private network and never exposed to access over the internet. This provides an additional network security layer and mitigates the risk of publicly exposing services (even through a firewall). Services configured to use private endpoints can be accessed from the same VNet, a peered VNet, and on-premises using S2S or ExpressRoute, if other security rules (such as NSGs for example) so allow. Not...