ACA now supports private endpoint connections, would like to switch to ACA from App Service. There are certain limitations at this point. - No Central policy exist for creating Private DNS Zone, OCIO team is looking into it. (https://chat.developer.gov.bc.ca/channel/public-cloud-how-to?msg=nAGDQDFxQQcsDQD5e) - Terraform does not have all the required capabilities and needs some workarounds (https://github.com/hashicorp/terraform-provider-azurerm/issues/28508#issuecomment-2723117786) cc @jujaga