Explanation: Yes, Yes, Yes NSG rules applied to the subnet hosting the private endpoint are not applied to the private endpoint.So the NSG1 doesn't limit storage access from either VM1 or VM2. https://docs.microsoft.com/en-us/azure/storage/common/storage-private-endpoints#network-security-group-rules