← SC-500: cloud and AI security
03 / 6 · 40 MIN

Private networks and diagnosis

Interpret rules, DNS, and paths without confusing a partial check with complete success.

Concept and mechanism

A connection traverses name resolution, routing, filtering, protocol negotiation, and the destination service. Diagnose by layer, recording source, destination, port, protocol, and time. In an NSG, the first matching rule by priority decides a new flow; lower numbers take precedence. Because the mechanism is stateful, changing rules does not mean terminating every existing connection. IP flow verify helps evaluate security and admin rules applicable to the interface but does not execute the complete application transaction. An Allow result remains compatible with routing failure, a stopped service, or another dependency. Preserve the distinction between observed evidence and a causal hypothesis.

Guided application

In fictional hybrid access, an Azure VM resolves SQL to the private endpoint while the on-premises client resolves to a blocked public address. Compare resolvers and forwarding to the private zone before granting more SQL permissions. After fixing DNS, also validate private routing and connectivity. Retain TLS-compatible names instead of distributing unmanaged hardcoded IPs. Azure Firewall processes rule types in order: a broad network rule can allow traffic before the intended application rule is reached. DDoS Protection and WAF address different layers. A change report should establish which flows pass, which are blocked, and how recovery works within the approved window.

IN PRACTICE

Allow from the rule tool plus application timeout are not contradictory: they measure different parts of the path.

Common pitfalls

Newest rule as highest priority; private DNS checked only from the healthy client; permanent hardcoded IP; DDoS as WAF.

Related topics: Identity, access, and governance · Storage, SQL, and keys · Agent and AI security

Take this idea with you

Test from the affected source and identify exactly what each result proves.

Create account

Reference: IP flow verification and rule evaluation · SC-500 guide updated 2026-05-13; Microsoft security documentation accessed 2026-09-30