With Private Link enabled - I get 403 (Forbidden). Why I am not getting 404 (when accessed from outside)

Mathew James 311 Reputation points
2022-09-26T10:24:40.007+00:00

Hi Everyone -

We have an internal application for a large enterprise and we have used App services and enabled Private endpoints. Things looked good as we are able to access from Inside and when accessed from outside we got 403 Forbidden access.

Although we thought this was fine, our security team indicated that with a 403 Forbidden, still one is able to hit from outside (public) although the page is not served. And they are looking for some thing 404 or page not found kind of error if hit from outside.

Any thoughts on how to completely Secure this ?

Or - with 403 Forbidden, is it completely secure ?

We are planning for Azure Front door with Premium and if required App gateway etc. But a direct hit to App service URL is the issue.

Any thoughts ?? Appreciate your help.

Thanks && Regards
-Mathew James

Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
462 questions
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
6,875 questions
{count} votes