Concept and mechanism
Controls with similar names act on different surfaces. An NSG allows or denies traffic using network properties and retains connection state. It does not interpret a SQL injection expression in an HTTP request as a WAF does. Azure Firewall can support central network policies; WAF protects web applications against attack patterns. DDoS protection addresses availability during network attacks, with scope and plan to confirm. These capabilities can complement each other without removing the need for secure code, identity management, and correct configuration. Draw the actual traffic path to identify where each control applies. A product outside that path does not provide the protection suggested by a diagram.
Guided application
For a fictional funds portal, separate customer traffic from administrative access. Bastion can connect to VMs over private addresses; its SKU and own requirements need validation. Do not interpret this as absence of every public IP in every possible design. During an intervention, removing an NSG rule does not necessarily terminate an existing session; test a new connection too. For keys, secrets, and certificates, Key Vault provides central management with access control. Inventory consumers and dependencies before rotating sensitive material. Placing a credential in a vault neither invalidates previously exposed copies nor guarantees the application uses the intended version.
The old SSH session continues; the new one fails. That can match a stateful NSG.
Common pitfalls
WAF as every-protocol filtering; old session as proof of the current rule; vault storage as copy revocation.
Related topics: Posture, detection, and response · Classification, DLP, and retention
Choose controls by surface and validate actual behavior.
Reference: Network security groups · SC-900 objectives 2026-07-28; October 2026 update announced