Public and private azure paas service data exchange

Hello Team,
In Azure ecosystem, there is a green zone ( paas services supporting vnet/private endpoint) or grey zone where endpoints are public. Is there any service from Azure which can validate the request coming from public resources, and connect to green zone on only private endpoint.
As an example, we have API management for API nodes, or as an Azure front door.
