Microsoft Defender for Cloud
Cloud and workloads

Configure private endpoints with Microsoft Security Private Link

In brief

The page updates prerequisite wording and links, clarifies the procedure for existing Security Private Link resources, and explains that the DNS command verifies resolution to a private IP address.

What Defender admins need to know

Administrators can use the revised guidance to configure and validate private endpoints; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

title: Configure private endpoints with Microsoft Security Private Link description: Configure private endpoints with Microsoft Security Private Link to securely connect your virtual network to Microsoft Defender for Cloud. ms.topic: how-to ms.date: 05/26/07/03/2026 ms.custom: msecd-doc-authoring-1013 #customer intent: As a security administrator, I want to configure a private endpoint for Microsoft Defender for Cloud so that Defender traffic stays within my private network.

ai-usage: ai-assisted

Configure private endpoints with Microsoft Security Private Link

Use a private endpoint in Azure Private Link with Microsoft Security Private Link. This setupprivate endpoint configuration connects workloads in your private network to Microsoft Defender for Cloud over Azure Private Link.

Before you begin, make sure that:

Create a private endpoint using a Security Private Link resource (Azure portal)

You can create a private endpoint while creating a Security Private Link resource in the Azure portal.

If you already have a Security Private Link resource, create a private endpoint for an existing Security Private Link resource.skip this procedure and follow the "Create a private endpoint for an existing Security Private Link resource (Azure portal)" section later on this page, which walks you through creating a private endpoint separately and connecting it to your existing resource.

To create a private endpoint while creating a Security Private Link resource:

To validate private endpoint DNS resolution:

From a workload connected to the virtual network, run:run the following command to verify that the Microsoft Defender for Cloud API hostname resolves to a private IP address through DNS:

nslookup api.cloud.defender.microsoft.com