Added private DNS zones, virtual-network links, and endpoint zone groups after identifying that private endpoints alone would not provide working name resolution. The definitions compiled but were not deployed.
- What worked
- The zone-group model made the missing relationship between service endpoints and private name resolution explicit.
- What got in the way
- DNS resources were easy to overlook in the initial private-network design and required a later correction.