Skip to content

[Feature request] Support approvalReference (privateEndpointId) on private endpoint connection (approval by reference) #34148

Description

@ajoyduwary

Preconditions

  • No need to upgrade Python SDK or the Python SDK is ready.

Related command

az network private-endpoint create (primary — sets approvalReference.privateEndpointId on the manual connection) and az network private-endpoint update (parity).

Resource Provider

Microsoft.Network/privateEndpoints

Description of Feature or Work Requested

Cli support for new property added approvalReference while creating Private Endpoint.

Direct main links:

• https://github.com/Azure/azure-rest-api-specs/blob/main/specification/network/resource-manager/Microsoft.Network/Network/Common/main.tsp
• https://github.com/Azure/azure-rest-api-specs/blob/main/specification/network/resource-manager/Microsoft.Network/Network/stable/2026-01-01/common.json
• https://github.com/Azure/azure-rest-api-specs/blob/main/specification/network/resource-manager/Microsoft.Network/Network/stable/2026-01-01/virtualNetwork.json
• https://github.com/Azure/azure-rest-api-specs/blob/main/specification/network/resource-manager/Microsoft.Network/Network/stable/2018-10-01/vmssNetwork.json

Minimum API Version Required

2026-01-01

Swagger PR link / SDK link

Azure/azure-rest-api-specs#45604

Request Example

# PE-B inherits PE-A's approved connection via approval-by-reference (min API 2026-01-01)
az network private-endpoint create \
  --name PE-B \
  --resource-group myRG \
  --vnet-name myVnet --subnet mySubnet \
  --private-connection-resource-id <PLS resource id> \
  --connection-name conn \
  --manual-request true \
  --approval-reference-id /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/privateEndpoints/PE-A

Target Date

2026-10-30

PM Contact

N/A

Engineer Contact

ajoyduwary

Additional context

No response

Activity

  1. yonzhan commented on Sep 29, 2026

    @yonzhan
    Collaborator

    Thank you for opening this issue, we will look into it.

  2. added this to the Backlog milestone on Sep 29, 2026
  3. microsoft-github-policy-service commented on Sep 30, 2026

    @microsoft-github-policy-service
    Contributor

    🔔 Routing this issue to @Azure/act-quality-productivity-squad.

  4. ajoyduwary commented on Sep 30, 2026

    @ajoyduwary
    MemberAuthor

    Proposed CLI surface for approvalReference (approval by reference)

    approvalReference.privateEndpointId lives on manualPrivateLinkServiceConnections[].properties and is set at PE create time, so this is a new parameter on existing commands, not a new command.

    Command Change
    az network private-endpoint create Primary — add --approval-reference-id mapping to manualPrivateLinkServiceConnections[0].properties.approvalReference.privateEndpointId. Valid only with --manual-request true.
    az network private-endpoint update Parity — same wiring.

    Out of scope: az network private-endpoint-connection approve/reject/list/show operate on the provider/PLS side of an existing connection and do not carry approvalReference.

    Behavior (min API 2026-01-01): if the referenced PE's connection is Approved, the new PE is auto-approved at creation; if it is Pending, NRP returns HTTP 400 ApprovalReferenceConnectionNotApproved. Validated end-to-end via an Armstrong (AzAPI) onboarding test against Microsoft.Network/privateEndpoints@2026-01-01.

    Suggested param naming: --approval-reference-id (ARM resource id of the reference private endpoint). Alias consideration: --approval-reference.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions