Skip to content
Networking pep

Private endpoint naming convention

The CAF abbreviation for Private endpoint is pep. Names can be 2 to 64 characters long and allow alphanumerics, hyphens and underscores. The name must be unique within the resource group.

Naming rules

CAF abbreviation pep
Length 2 to 64 characters
Allowed characters Alphanumerics (a-z, A-Z, 0-9), hyphens, underscores
Scope of uniqueness Unique within the resource group
CAF pattern pep-{workload}-{environment}-{region}-{instance}

Rules follow Microsoft's resource naming rules and CAF abbreviations. Some resource types have extra start/end character restrictions, so verify against the official docs before locking in a convention.

Naming Networking resources

Networking has the widest split between globally unique, DNS facing resources (a public IP with a DNS label, a CDN or Front Door endpoint, a Traffic Manager profile) and resources scoped to their parent rather than the resource group, subnets, NSG security rules, and route entries all fall into the second group, so the same rule name can safely repeat across different NSGs without colliding.

Hub and spoke architectures generate a lot of near identical resources, one NSG, one route table, one peering per spoke, so the naming pattern has to carry the spoke identity clearly, since that is the only thing telling twenty otherwise similar resources apart. A common mistake is naming a peering connection only from one side, to-hub, when peerings are directional pairs and both ends need distinct, symmetric names to stay legible during an audit.

Example names

Generated by the same engine as the name generator, so length and character rules are already applied.

Scenario Generated name Length
Payments API, production pep-payments-prod-eus-001 25/64
Web app, development pep-webapp-dev-weu-002 22/64
Analytics with company prefix pep-contoso-analytics-stage-uks-001 35/64

Naming in Terraform and Bicep

Build the name from variables so one module produces the right name in every environment.

Terraform
locals {
  private_endpoint_name = "pep-${var.workload}-${var.environment}-${var.region}-001"
}
Bicep
var privateEndpointName = 'pep-${workload}-${environment}-${region}-001'

Generate Private endpoint names for your workload

Free, no login. Validation and Terraform, Bicep, or CSV export included.

Open in the generator →

Related Networking resources

See the full list of Azure resource naming rules or read the complete CAF naming guide.