How to Configure DNS Forwarding for Azure Arc Private Endpoints
Question details
The user needs to identify the correct DNS zone names and IP addresses to configure on-premises conditional forwarders for Azure Arc using a private endpoint and VPN.

- Product
- Azure Arc
- Device & OS
- not provided
- Scenario
- Setting up Azure Arc over a private network connection (VPN/ExpressRoute) and integrating on-premises DNS.
- Observed behavior
- The user is seeking specific DNS configurations and parameters to successfully resolve Azure Arc private endpoints from their local network.
Ensure you have administrative privileges to your on-premises DNS server, access to the Azure portal, and a clear map of your network topology including VPN and private endpoint details.
Consult Azure Documentation and Microsoft Q&A Forums
Because Azure Arc private networking requires specific infrastructure configurations, the best approach is to identify the required Azure DNS zones and consult dedicated Azure support channels.
Configuring DNS forwarding for Azure Arc involves specific private DNS zones (e.g., privatelink.his.arc.azure.com) that must resolve to your Azure DNS inbound resolver IP addresses.
Since this relates to Azure infrastructure and not standard Microsoft 365 services, dedicated Azure forums are the best place for topology-specific assistance.
Review the official Microsoft Learn documentation for Azure Arc network requirements to find the exact list of 'privatelink' DNS zones required for your specific Arc services.
Open your on-premises DNS Manager. Right-click 'Conditional Forwarders', select 'New Conditional Forwarder', and input the required Azure Arc private DNS zone names along with the IP addresses of your Azure DNS inbound resolvers.
If you experience resolution issues, navigate to the Azure Microsoft Q&A forum. Post your question including relevant tags, your network topology, private endpoint configuration, and current DNS forwarder details.

Document Your Network Topologies with WPS Office
While configuring complex Azure networking environments, you need reliable software to manage your network diagrams, configuration scripts, and IT documentation. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for all your professional documentation needs.
- 1. Download the software: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install the suite: Run the setup file and follow the straightforward on-screen instructions to complete the installation.
- 3. Start documenting: Open WPS Writer or Spreadsheet to begin drafting your Azure Arc deployment plans and network topology logs.

Frequently Asked Questions
What are the common DNS zones required for Azure Arc private endpoints?
Depending on the Azure Arc services you use, common zones include privatelink.his.arc.azure.com, privatelink.guestconfiguration.azure.com, and privatelink.dp.kubernetesconfiguration.azure.com. You should refer to the latest Azure documentation for a comprehensive list.
Why do I need a conditional forwarder for Azure Arc?
A conditional forwarder ensures that any DNS queries originating from your on-premises network for specific Azure domain names are sent directly to Azure's DNS resolvers. This guarantees proper private IP resolution over your VPN or ExpressRoute connection.
Can standard Microsoft 365 support help with Azure Arc DNS issues?
No. Azure Arc and private networking are part of Azure infrastructure. You must utilize Azure support channels or the Azure Microsoft Q&A forum with the appropriate tags to get accurate assistance.




