Elastic Cloud Serverless extends support to Azure Private Link

As of August 4, 2026, Elastic Cloud Serverless officially supports Azure Private Link, providing private connectivity for Azure workloads without exposing Elastic endpoints to the internet. This feature, already available for AWS PrivateLink since February 2026, represents a significant step in the integration between Elastic and major cloud providers.

How Azure Private Link works

When you associate an Azure private connection policy with a Serverless project, all traffic between the Azure virtual network and Elastic travels within the Azure network. Elastic's public endpoints remain accessible, but any request not coming from a corresponding private endpoint or IP filter is rejected with a 403 Forbidden error. Unlike AWS, where the policy is optional, it is mandatory on Azure.

The connection occurs through an Azure private endpoint in the VNet. Elastic hosts a Private Link service, while the user creates the private endpoint in their own subscription. Elastic automatically approves the connection when the VNet is whitelisted by a user-created policy.

Configuration and limitations

Configuration requires creating an Azure private endpoint pointing to the Elastic Private Link service, updating the DNS to resolve Elastic hostnames to the private IP address of the endpoint, and creating a private connection policy in Elastic Cloud with the Resource name and Resource ID of the endpoint.

Currently, support for Azure Private Link is not available in the northeurope region due to an Azure limitation, despite Elastic Cloud Serverless being operational in that area.

Packages and availability

Private connectivity for Serverless is included in the following tiers with no additional costs starting August 4, 2026:

  • Observability Serverless projects: require Observability Complete

For other types of projects, such as Elasticsearch Serverless, the feature is available without tier requirements. Projects created before August 4, 2026 are exempt from these requirements and can use traffic filtering without restrictions for their entire duration.

Integration with other cloud providers

With the addition of Azure Private Link, Elastic continues to invest in network security across major cloud providers. AWS PrivateLink has been available for Serverless since February 2026, and further integrations are planned for the future. For a complete overview of private connectivity features, it is recommended to consult the official documentation.

Frequently asked questions

Does Azure Private Link also work for Elastic Cloud Hosted distributions? Yes, but this release specifically focuses on Elastic Cloud Serverless. The feature for Hosted distributions is available through a separate API.

Can you use both an IP filter and a private connection policy on the same project? Yes, each request must match at least one attached policy. Traffic from a corresponding private endpoint matches the private connection policy, while traffic from an IP range matches the IP filter. Traffic that does not match either policy is rejected.

Is a policy on Azure required to ensure a private connection? Yes, for Azure Private Link, you need to create a policy in Elastic Cloud Console and add the Resource name and Resource ID of the private endpoint before Elastic approves the connection. This differs from AWS, where the policy is optional. By associating the policy with specific projects, you can filter traffic from specific private endpoints.

Do you need a separate endpoint per project or per type of solution? A single private connection policy referencing the Azure private endpoint can be attached to multiple projects. Each Serverless project has its own private hostname that uses a private connection. For more details on endpoint configuration, see the documentation.

The release and timing of any feature described in this post remain at Elastic's discretion. Some features or improvements may not be available or may experience delays.

Implications and Strategies for Adopting Azure Private Link in Elastic Cloud Serverless

The introduction of Azure Private Link in Elastic Cloud Serverless represents a significant step toward securing and optimizing cloud infrastructures. Companies using Elastic for data analysis, security, or observability can now benefit from private connectivity that reduces the risks associated with exposing public endpoints.

Advantages for Security and Performance

Private connectivity offers numerous advantages:

  • Reduced public exposure: By eliminating the need to expose public endpoints, organizations minimize the risk of direct attacks.
  • Reduced latency: Traffic stays within the Azure network, improving performance for critical applications.
  • Compliance: Many industry regulations require that sensitive data not traverse public networks, making this solution ideal for sectors such as healthcare and finance.

Considerations for Companies

Before implementing Azure Private Link, companies should evaluate:

  • Compatibility with existing infrastructures: Verify that current security and monitoring solutions support private connectivity.
  • Indirect costs: Although the feature is included in the specified tiers, implementation may require additional resources for configuration and management.
  • Migration planning: For projects created before August 4, 2026, evaluate whether to maintain existing configurations or adopt new security policies.

Future Perspectives and Integrations

Elastic is continuing to expand its private connectivity capabilities, with further integrations planned for other cloud providers. This trend reflects a growing demand for solutions that combine advanced security and operational flexibility. Companies planning to adopt Elastic Cloud Serverless should monitor Elastic's updates to take full advantage of these developments.

Practical Examples of Implementation

A company managing sensitive data might configure Azure Private Link for its Observability Serverless projects, ensuring that all queries and analyses occur within a private network. At the same time, it might maintain IP filters for less critical projects, creating a hybrid environment that balances security and convenience.

For further technical details and best practices, it is recommended to consult Elastic's official documentation.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product under Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.