Three Azure services all "block traffic", but at different layers and in different places. What each one inspects, how they fit together, and three exam traps.
By Tony Rough
A network security group, Azure Firewall and a web application firewall can all stop traffic, so exam scenarios offer all three as answers. They aren’t alternatives: each looks at a different part of the traffic, in a different place.
An NSG is a list of allow and deny rules matched on the five-tuple: source, source port, destination, destination port and protocol. Rules have a priority from 100 to 4096, lower numbers first, and processing stops at the first match. Default rules (priority 65000 and up) allow traffic within the virtual network and out to the internet, and deny other inbound traffic.
Storage or Internet stands for a set of IP prefixes that Microsoft keeps up to date, so you don’t maintain address lists yourself.An NSG can’t read a domain name, a URL or the content of a request.
Azure Firewall is a firewall as a service, with built-in high availability, for east-west and north-south traffic. For production, Microsoft recommends a hub-and-spoke design: the firewall in its own hub virtual network, workloads in peered spokes.
It only sees traffic sent to it, so each workload subnet needs a route table with a user-defined route for 0.0.0.0/0, next hop Virtual appliance, at the firewall’s private IP address.
Rules come in three kinds: DNAT (inbound, to a private server), network (addresses, ports, service tags) and application (FQDN filtering for HTTP/S and MSSQL). Network rules can use FQDNs for other protocols, such as SSH, if DNS proxy is on.
The three SKUs:
Don’t confuse those routes with the firewall’s own forced tunnelling, which sends its internet-bound traffic on to an on-premises device and needs the Firewall Management network interface.
A WAF inspects HTTP and HTTPS requests arriving at a web app. You’ll meet it on Application Gateway (regional) and Azure Front Door (at Microsoft’s global edge). A WAF policy holds:
Detection mode only logs matches; prevention mode blocks them. Microsoft suggests running a new WAF in detection mode briefly first, to find false positives.
A typical design layers all three: a WAF on Front Door or Application Gateway in front of the web tier, Azure Firewall in the hub with a user-defined route on each spoke subnet, and NSGs on the spoke subnets, kept short with ASGs and service tags.
| You need… | Choose |
|---|---|
| Allow or deny ports between subnets or VMs | NSG (with ASGs and service tags) |
| Restrict outbound traffic to named websites (FQDNs) | Azure Firewall application rules |
| One central inspection point for every spoke | Azure Firewall in the hub, plus UDRs |
| Decrypt and inspect outbound HTTPS, or IDPS | Azure Firewall Premium |
| Block SQL injection or XSS against a web app | WAF on Application Gateway or Front Door |
| Log web attacks without blocking yet | WAF in detection mode |
The AZ-700 study guide gives each service its own chapter: NSGs (chapter 13), Azure Firewall (chapter 14) and WAF (chapter 15). The SC-500 study guide covers them in chapters 7, 9 and 12, and the AZ-104 study guide covers NSGs, ASGs and service tags in chapter 12. Facts checked against Microsoft Learn on 8 October 2026.
Microsoft has confirmed that Always Encrypted with Intel SGX enclaves in Azure SQL Database retires on 31 October 2027, and that App Service support for Java 8, 11 and 17 ends on 1 September 2027. Defender for Storage can now scan individual blobs and containers on demand, and Application Gateway WAF inspects IPv6 traffic in preview.
Both connect your on-premises network to Azure, but one runs encrypted over the internet and the other runs privately through a provider. How each works, the SKU changes, encryption, failover, Virtual WAN and three exam traps.
Three Azure governance controls that people mix up. RBAC decides who can act, Azure Policy decides what a resource may look like, and locks stop changes even by an Owner. Scopes, effects, exemptions, remediation, deny assignments and three traps.
The October review of Microsoft's announcements found two changes that affect the AZ-305 guide. The retirement date for Application Insights URL ping tests has moved, and Azure IoT Central is being retired.
Both lock an Azure service down to your virtual network, but they work in completely different ways. How each one works, the on-premises trap, DNS, data exfiltration, and a five-second way to choose.