azure_validate_private_endpoints
Validate Azure Private Endpoint and Private Link security by checking connection status, DNS integration, network policies, and public access exposure, returning coverage and risk warnings.
Instructions
NEW in v1.14.0 Validate Private Endpoint and Private Link security configurations. Checks: approved/pending connections, network policies enforcement, DNS integration (private DNS zones), public access bypass, subnet delegation, private endpoint policies, service-specific configurations (Storage, SQL, KeyVault, CosmosDB). Returns: private endpoint coverage, pending approval risks, DNS misconfiguration warnings, public access exposure.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| subscriptionId | Yes | Azure subscription ID | |
| resourceGroup | No | Optional: Filter by specific resource group | |
| serviceTy | No | Optional: Filter by service type (e.g., 'Microsoft.Storage', 'Microsoft.Sql') | |
| validateDNS | No | Validate private DNS zone configuration and integration. Default: true | |
| format | No | Output format: 'markdown' (default, human-readable) or 'json' (machine-readable) |