Azure Private and Service endpoints

Hi All,

What’s the recommendation for configuring Azure’s service and private endpoints? I can’t see an obvious role or task for this.
I want to configure my storage accounts to allow direct access from VMs without traversing this internet.

Thanks
Nick