@Shah, Gaurang , By design Azure private endpoint is not exposed to public internet. So, there is limitation on applying NSG above a private endpoint. But this limitation should not affect the communication between subnets in same VNET and should work well on approved authorization.
----------
Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.