A customer reports that after enabling a Private Endpoint for Azure Key Vault, their Azure Function (in a different VNet) cannot reach Key Vault.VNet peering exists between the two VNets.What should you check first?