# Connecting to UiPath using private link

> Use Azure Private Link to route traffic from your Azure Virtual Network (VNet) to Automation Cloud services through a private network path, keeping traffic off the public internet. This configuration is ideal when your organization requires network isolation for traffic originating from your Azure environment. The connection to `cloud.uipath.com` stays on a private network path through your private endpoint, though other UiPath subdomains may still resolve to public IP addresses depending on your DNS configuration.

Use Azure Private Link to route traffic from your Azure Virtual Network (VNet) to Automation Cloud services through a private network path, keeping traffic off the public internet. This configuration is ideal when your organization requires network isolation for traffic originating from your Azure environment. The connection to `cloud.uipath.com` stays on a private network path through your private endpoint, though other UiPath subdomains may still resolve to public IP addresses depending on your DNS configuration.

:::important
Azure Private Link is currently available in the **Europe** region only. Support for additional regions will be announced as the rollout expands.
:::

## Traffic flow

Traffic follows this path:

1. Client devices or VMs (for example, Robots, Task Mining devices, browsers)
2. Customer VNet
3. Customer private endpoint
4. UiPath regional gateway (private connectivity entry point)
5. UiPath backend services

## Available regions

When you create the private endpoint, connect to the correct regional gateway:

| Location | Region | Resource ID | Subresource |
| --- | --- | --- | --- |
| **Europe** | **West Europe** (Primary) | `/subscriptions/05f74eb7-7054-4e72-a744-2ce5d7180bd7/resourceGroups/plt-prd-gate-we-01-g-rg/providers/Microsoft.Network/applicationGateways/plt-prd-gate-we-01-g-appgw` | `plt-prd-gate-we-01-g-appgw-fip-config1` |
| **Europe** | **North Europe** (Secondary) | `/subscriptions/05f74eb7-7054-4e72-a744-2ce5d7180bd7/resourceGroups/plt-prd-gate-ne-01-g-rg/providers/Microsoft.Network/applicationGateways/plt-prd-gate-ne-01-g-appgw` | `plt-prd-gate-ne-01-g-appgw-fip-config1` |

## High availability and disaster recovery (HADR)

If you use two data centers, create a private endpoint for each region:

* Connect your primary data center to the **West Europe** gateway.
* Connect your secondary data center to the **North Europe** gateway.

## Failover handling

UiPath does not automatically update which private endpoint is used if an application gateway experiences issues. Creating two private endpoints upfront makes it easier to switch between primary and failover configurations — the only change required is updating the `cloud.uipath.com` DNS record to the IP address allocated to the respective private endpoint.

:::note
Setting a low TTL (for example, 60 seconds) for the `cloud.uipath.com` DNS record minimizes disruption during failover.
:::
