AZ

azure-private-link

Expert guidance for Azure Private Link architecture and security.

Install

mkdir -p .claude/skills/azure-private-link && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/12689" && unzip -o skill.zip -d .claude/skills/azure-private-link && rm skill.zip

Installs to .claude/skills/azure-private-link

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Expert knowledge for Azure Private Link development including best practices, decision making, architecture & design patterns, limits & quotas, security, and configuration. Use when configuring Private Endpoints, DNS zones, SNAT bypass, Network Security Perimeters, or Azure Private Resolver, and other Azure Private Link related development tasks. Not for Azure Virtual Network (use azure-virtual-network), Azure VPN Gateway (use azure-vpn-gateway), Azure ExpressRoute (use azure-expressroute), Azure Virtual WAN (use azure-virtual-wan).
538 chars✓ has a “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Intermediate

Key capabilities

  • Configure Private Endpoints
  • Design DNS architectures for Private Endpoints
  • Manage Private Link capacity limits and quotas
  • Set up RBAC for Private Endpoints and Private Link
  • Configure subnet and service network policies
  • Monitor Private Link connectivity data

How it works

This skill retrieves documentation content using either mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage with a specified query string.

Inputs & outputs

You give it
Query string for documentation fetch
You get back
Markdown documentation content

When to use azure-private-link

  • Configuring private endpoints
  • Designing secure network architecture
  • Managing Azure private DNS zones

About this skill

Azure Private Link Skill

This skill provides expert guidance for Azure Private Link. Covers best practices, decision making, architecture & design patterns, limits & quotas, security, and configuration. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
Best PracticesL34-L38DNS design and configuration guidance for private endpoints, including zone setup, name resolution patterns, split-horizon DNS, and avoiding common DNS misconfigurations with Private Link
Decision MakingL39-L44Guidance on choosing perimeter access modes and designing Azure Private Link setups, focusing on security tradeoffs, cost optimization, and migration/transition considerations.
Architecture & Design PatternsL45-L49Designing DNS architectures for Private Endpoints using Azure Private Resolver, including name resolution patterns, forwarding rules, and integration with on-premises or hybrid networks
Limits & QuotasL50-L56Details on Private Link/Endpoint capacity limits, per‑VNet scaling (High Scale), resource availability checks, and common behaviors/FAQs around quotas and constraints
SecurityL57-L64RBAC setup, security best practices, and traffic inspection/control for Private Endpoints and Private Link using Azure roles, Network Security Perimeters, and Azure Firewall.
ConfigurationL65-L76Configuring Private Link/Endpoint behavior: subnet and service network policies, DNS records, SNAT bypass, routing, NSPs, diagnostics, and monitoring data for secure connectivity.

Best Practices

TopicURL
Apply DNS integration best practices for Azure Private Endpointshttps://learn.microsoft.com/en-us/azure/private-link/private-endpoint-dns-integration

Decision Making

TopicURL
Choose and transition Azure network security perimeter access modeshttps://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-transition
Optimize Azure Private Link design for cost and securityhttps://learn.microsoft.com/en-us/azure/private-link/private-link-cost-optimization

Architecture & Design Patterns

TopicURL
Design DNS infrastructure for Private Endpoints with Azure Private Resolverhttps://learn.microsoft.com/en-us/azure/private-link/tutorial-dns-on-premises-private-resolver

Limits & Quotas

TopicURL
Check Azure Private Link service availability by resourcehttps://learn.microsoft.com/en-us/azure/private-link/availability
Increase Azure Private Endpoint per‑VNet limits with High Scalehttps://learn.microsoft.com/en-us/azure/private-link/increase-private-endpoint-vnet-limits
Azure Private Link limits, behaviors, and FAQshttps://learn.microsoft.com/en-us/azure/private-link/private-link-faq

Security

TopicURL
Configure RBAC permissions for Azure Network Security Perimeter operationshttps://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-role-based-access-control-requirements
Assign Azure RBAC roles for Private Endpoint and Private Link deploymenthttps://learn.microsoft.com/en-us/azure/private-link/rbac-permissions
Apply security best practices to Azure Private Linkhttps://learn.microsoft.com/en-us/azure/private-link/secure-private-link
Inspect and control Private Endpoint traffic using Azure Firewallhttps://learn.microsoft.com/en-us/azure/private-link/tutorial-inspect-traffic-azure-firewall

Configuration

TopicURL
Configure Private Link service Direct Connect routinghttps://learn.microsoft.com/en-us/azure/private-link/configure-private-link-service-direct-connect
Create and manage network security perimeters with Azure CLIhttps://learn.microsoft.com/en-us/azure/private-link/create-network-security-perimeter-cli
Configure subnet network policies for private endpointshttps://learn.microsoft.com/en-us/azure/private-link/disable-private-endpoint-network-policy
Configure privateLinkServiceNetworkPolicies for Private Linkhttps://learn.microsoft.com/en-us/azure/private-link/disable-private-link-service-network-policy
Configure and manage Azure Private Endpoint propertieshttps://learn.microsoft.com/en-us/azure/private-link/manage-private-endpoint
Reference for Azure Private Link monitoring datahttps://learn.microsoft.com/en-us/azure/private-link/monitor-private-link-reference
Enable and store Network Security Perimeter diagnostic logshttps://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-diagnostic-logs
Configure private DNS zone records for Azure Private Endpointshttps://learn.microsoft.com/en-us/azure/private-link/private-endpoint-dns
Configure SNAT bypass tags for Private Endpoint traffic via NVAhttps://learn.microsoft.com/en-us/azure/private-link/private-link-disable-snat

When not to use it

  • When working with Azure Virtual Network
  • When working with Azure VPN Gateway
  • When working with Azure ExpressRoute

Limitations

  • Does not cover Azure Virtual Network
  • Does not cover Azure VPN Gateway
  • Does not cover Azure ExpressRoute

How it compares

This workflow provides structured access to specific Azure Private Link documentation categories, unlike a general web search.

Compared to similar skills

azure-private-link side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
azure-private-link (this skill)01moNo flagsIntermediate
azure-firewall02moNo flagsIntermediate
azure-infra-review04moNo flagsIntermediate
azure-role-selector06moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

azure-firewall

MaRekGroup

Expert knowledge for Azure Firewall development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring DNAT/SNAT rules, TLS inspection, DNS proxy, hub-a

00

azure-infra-review

aldelar

Reviews Bicep modules, azure.yaml, and infrastructure changes for the KB Agent project. Checks naming, RBAC, module wiring, and doc sync. Use when working on infra/ or reviewing infrastructure PRs.

00

azure-role-selector

Tyler-R-Kendrick

|

00

cloud-architect

sickn33

Expert cloud architect specializing in AWS/Azure/GCP multi-cloud infrastructure design, advanced IaC (Terraform/OpenTofu/CDK), FinOps cost optimization, and modern architectural patterns. Masters serverless, microservices, security, compliance, and disaster recovery. Use PROACTIVELY for cloud architecture, cost optimization, migration planning, or multi-cloud strategies.

649

azure-deployment-preflight

github

Performs comprehensive preflight validation of Bicep deployments to Azure, including template syntax validation, what-if analysis, and permission checks. Use this skill before any deployment to Azure to preview changes, identify potential issues, and ensure the deployment will succeed. Activate when users mention deploying to Azure, validating Bicep files, checking deployment permissions, previewing infrastructure changes, running what-if, or preparing for azd provision.

746

terraform-azurerm-set-diff-analyzer

github

Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes. Use when reviewing terraform plan output for Azure resources like Application Gateway, Load Balancer, Firewall, Front Door, NSG, and other resources with Set-type attributes that cause spurious diffs due to internal ordering changes.

534

Search skills

Search the agent skills registry