You can't associate an NSG directly with the Private Endpoint NIC. The
best way to achieve what you want is to apply the NSG at the subnet
level and then have the rule you need in the subnet level NSG
referencing the specific IP for your Private Endp...