Top Gradient

PrivateLink for Snowflake Account on Azure

Organizations using Snowflake with Azure PrivateLink can still use connect SELECT to their Snowflake Account with a few extra steps. Please reach out to your SELECT account representative to start the process.

This guide walks you through enabling Azure PrivateLink between your Snowflake account and SELECT.

Prerequisites

  • Snowflake account running on Azure
  • Snowflake ACCOUNTADMIN role (required to run the authorization commands)
  • The Azure region of your Snowflake account (for example, eastus)

Run the following command in your Snowflake account as ACCOUNTADMIN, then share the output with your SELECT representative:

1SELECT SYSTEM$GET_PRIVATELINK_CONFIG();

The output is a JSON object. SELECT needs the following two fields from it to create a private endpoint on their side before authorization can proceed:

FieldDescriptionExample
privatelink-account-urlYour account locator and Azure regioneua49794.east-us-2.privatelink.snowflakecomputing.com
privatelink-pls-idYour Private Link Service aliassf-pvlinksvc-azeastus2.xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx.eastus2.azure.privatelinkservice

Step 2 — Wait for SELECT to create a private endpoint

SELECT uses the configuration from Step 1 to provision a private endpoint in their Azure environment, connecting to your Snowflake instance. SELECT will contact you once the endpoint is ready and provide the information needed for Step 3.

Step 3 — Authorize SELECT's private endpoint

Once SELECT provides the SYSTEM$AUTHORIZE_PRIVATELINK command, run it in your Snowflake account as ACCOUNTADMIN:

1SELECT SYSTEM$AUTHORIZE_PRIVATELINK('<private_endpoint_resource_id>', '<azure_access_token>');

Step 4 — Add your Snowflake account connection

Add your Snowflake account connection in SELECT. In the Account Identifier field, use the Private Link account name format below — instead of the standard Snowflake account URL:

1<account_locator>.<region>.privatelink

For example, if your account locator is abc12345 and your region is eastus:

1abc12345.eastus.privatelink

Step 5 — Network policy (if applicable)

If your Snowflake account has a network policy restricting inbound connections, add SELECT's private IP ranges to the allowlist:

IP rangePurpose
`10.124.0.0/28`SELECT backend
`10.1.128.0/17`The periodic job that reads your Snowflake metadata

Get up and running in less than 15 minutes

Connect your Snowflake, Databricks, or BigQuery account and instantly understand your savings potential.

CTA Screen