Search Service authorization fails (in environments where policy prohibits private endpoint connections from other subscriptions).

443 0 Reputation points
2024-09-05T00:39:58.9633333+00:00

To achieve private sending/receiving between “Storage Account” and “Search Service” currently

To use the Search Service's shared private link, you need to create a shared private link between the storage account and the Search Service.

To use the Search Service's shared private link, you need to approve the shared private link created on the other side of the storage account.

The shared private link must be approved by the storage account.

In this case, we cannot approve the private link because it violates the policy of “prohibiting PrivateEndpoint connections when the subscriptions are different”.

However, the approval operation is working for the shared private link between “SQL Server” and “Search Service” and other services.

Translated with DeepL.com (free version)

Azure AI Search
Azure AI Search
An Azure search service with built-in artificial intelligence capabilities that enrich information to help identify and explore relevant content at scale.
1,066 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
918 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. SnehaAgrawal-MSFT 21,766 Reputation points
    2024-09-18T06:57:15.79+00:00

    @443 Apologies for late response here! Could you confirm if this an Azure policy that you have enabled?

    Share private link, by design, is from our VNet, ie Microsoft internal, to the customer's, so it is expected to be in 2 different subscription.

    If you have a policy auditing or preventing this external from search, it would need to be relaxed for some resources, or those resource should be provisioning in a scope where the policy doesn't apply.

    Let us know.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.