Hello , Welcome to MS Q&A
Based on the information provided, there is no indication that conditional forwarders for Azure DNS Private Resolver should only point to the root domain rather than regional. You can configure on-premises DNS servers with conditional forwarders pointing to the DNS Private Resolver service's inbound endpoint IP address in Azure to forward the request to the Azure Private DNS zone.
Recommendations:
- Configure conditional forwarders based on the specific Azure Private DNS zones required for your use case.
- Ensure that the Azure Private DNS zones are created within a global connectivity subscription, including the zones required for accessing Azure PaaS services via a private endpoint.
References:
- DNS for on-premises and Azure resources
- Configure DNS forwarding for Azure Files using VMs or Azure DNS Private Resolver
- Administer DNS and create conditional forwarders in a Microsoft Entra Domain Services managed domain
- Resolve Azure and on-premises domains
Please let me know if any questions
Kindly accept answers if it helps
Thanks
Deepanshu