HOTSPOT You have two Azure subscriptions named Subscription1 and Subscription2. There are no connections between the virtual networks in two subscriptions. You configure a private link service as shown in the privatelinkservice1 exhibit. (Click the privatelinkservice1 tab.) 


Not convinced it's 10.3.0.7 for Subscription2 users. They connect with the private endpoint IP from their vnet, not the provider's NAT IP, so that statement should be No. The backend pool detail is a classic trap here-resources must be in the load balancer backend pool for Private Link to work right. Anyone see a case where Azure let users connect via NAT directly?
Pretty sure that's correct since the private endpoint is created and maybe exposed that IP, as seen in practice sometimes. But let me know if there's a catch with how Azure handles NAT IPs here.
