Skip to main content

Configure Azure Private Endpoint for an App Volumes Application Storage Account

If the private endpoint status of a storage account is Not Configured, then use the Configure Private Endpoint option to configure a private endpoint for the storage account.

The Azure private endpoint solution can be used to securely access storage accounts and file shares. Using the Horizon Universal Console, you can configure a private endpoint for a storage account either when deploying a new Microsoft Azure Edge or for an existing Microsoft Azure Edge deployment. For more information about the private endpoint required for accessing App Volumes storage accounts, see Azure Private Endpoint for an App Volumes Application Storage Account.

Note: It is recommended that after configuring the private endpoint, end users log out from their virtual machines and log in again.

  1. In the Horizon Universal Console, click Capacity.

  2. Select the Horizon Edge where the private endpoint must be configured.

  3. Navigate to the App Volumes Application Storage section.

  4. In the Azure Storage Accounts table, click the overflow icon (three vertical dots) for the storage account whose private endpoint status is either Not Configured or Disconnected.

  5. Click Configure Private Endpoint.

  6. In the Configure Storage Account Private Endpoint window, ensure that all requirements are met and select the Permissions check box.

    For more information about these requirements, see Azure Private Endpoint for an App Volumes Application Storage Account.

  7. Select a virtual network from the Private Endpoint vNet drop-down menu.

  8. Select a subnet from the Subnet drop-down menu.

  9. Click Save.

    Status of the private endpoint is Connected.

After configuring the private endpoint for a storage account in an existing Horizon Edge deployment, perform the following steps prior to deactivating the public network access of the storage account:

  • Ensure that the connectivity between the storage account and Horizon Edge and storage account and each of the desktop pool is successful.
  • End users with existing application attachments, which were assigned before the private endpoint is configured, must log out from their virtual machines.

Note: If you are working in the Azure portal, navigate to the Storage Accounts > Security + networking > Firewalls and virtual networks section and set the Public network access option for the specific storage account to Disabled. For more information, see the corresponding Microsoft documentation.

If there are connectivity issues between any of the existing desktop pools and file shares affecting application delivery and you want to revert to the public network access for the storage account until you troubleshoot these issues, then you can use the Remove Private Endpoint option. This option removes the configured private endpoint and automatically enables public network access for the storage account in the Azure portal. After fixing the issues, you can configure the private endpoint using the Configure Private Endpoint option.

Was deze pagina nuttig?

Feedback geven over dit onderwerp

Was dit onderwerp nuttig?

Vermeld geen persoonlijke of vertrouwelijke informatie.

Link genereren…