How to disable the publicNetworkAccess for the existing cosmos database

Viewed 1657

Can one please let me know on How to disable the publicNetworkAccess for the existing cosmos database.

This is to make sure that the cosmos database is not exposed on the public network and will be configuring a private endpoint to restrict the access of the resource.

enter image description here

enter image description here

3 Answers

You could use the az cli command: az cosmosdb update to disable the publicNetworkAccess for the existing cosmos database.

az cosmosdb update --name MyCosmosDBDatabaseAccount --resource-group MyResourceGroup --enable-public-network false

enter image description here

According to Docs,

To make sure that public network access is disabled even before the creation of private endpoints, you can set the publicNetworkAccess flag to Disabled during account creation

Here is an example

Also note

Note that this flag takes precedence over any IP or virtual network rule; all public and virtual network traffic is blocked when the flag is set to Disabled, even if the source IP or virtual network is allowed in the firewall configuration.

You should be able to update this setting on the portal. Please see the screenshot below.

enter image description here

Related