By default, communication across subnets in the same VNET is not restricted. Refer: Azure virtual network traffic routing | Microsoft Learn
Customers can see MongoDB vCore and modify its configuration in Azure Portal (i.e., control plane access). But there is no way to see data within it from Azure Portal (this would data plane access). Private endpoints apply to data plane only. Control plane is publicly accessible unless this setting is enabled, which would be somewhat rare.