# Coordinate PROXY v2 across shared Private Link service backends

> Review protocol parsing and shared load-balancer dependencies before enabling consumer connection metadata.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-178-coordinate-proxy-v2-across-shared-private-link-service-backends/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:58+00:00
- Modified: 2026-09-10T00:55:36+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Review protocol parsing and shared load-balancer dependencies before enabling consumer connection metadata.

## Potentially affected

Standard Azure Private Link services sharing load balancers or backend pools.

## DSE recommendation

Inventory every sharing Private Link service and validate backend PROXY v2 parsing before changing the setting.

## Article

## Source facts

Private Link service translates consumer source addresses to provider-side NAT addresses. PROXY v2 can convey the original source and endpoint LinkID, but the backend must parse the added header; a mismatch between the service setting and backend expectation causes requests to fail.

Microsoft warns that enabling PROXY v2 affects shared load-balancer and backend arrangements. Other Private Link services sharing them must be configured consistently, or health probes fail. The header is also included in HTTP/TCP health probes. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/private-link/private-link-service-overview).

## Applicability

Use this review for standard load-balancer-backed Private Link services, not the separate Direct Connect preview. Map sharing services and backend consumers before considering the setting a change to only one endpoint.

## DSE recommendation

DSE recommends a compatibility change plan agreed by the service and application owners. Record which backends expect the header, which services share their pool, and how connection metadata will be interpreted. Preserve the prior configuration and define a coordinated restoration sequence if parsing or probes fail.

## Verification

In a representative test, inspect backend request handling, reported connection metadata, and health probes before and after enabling the protocol. Exercise each sharing service rather than just the first one changed. Confirm requests work and the observed source/LinkID correlation is correct; do not treat that correlation alone as application authorization.

## Official references

[Microsoft Learn: What is Azure Private Link service?](https://learn.microsoft.com/en-us/azure/private-link/private-link-service-overview). Source retrieved September 9, 2026.

## Primary reference

- Name: What is Azure Private Link service? | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/private-link/private-link-service-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Coordinate PROXY v2 across shared Private Link service backends,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-178-coordinate-proxy-v2-across-shared-private-link-service-backends/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
