Allow and deny rules for inbound App Service traffic, matched on IP range, service tag or subnet. They can, for instance, restrict an app to a corporate NAT's public addresses.
Also called App Service access restrictions.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Access restrictions in context, with comparison tables and the common traps.
Terms in this definition
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
- App Service
Managed PaaS hosting for web apps and Web App for Containers, run in a sandbox without OS access. Deployment slots and autoscale start at the Standard tier.
- RANGE
Usable only in visual calculations, this DAX function picks a span of rows along an axis counted from the current one, say the previous six. Think of it as a simpler WINDOW, handy for moving totals.
- Service tag
A set of IP prefixes for an Azure service, kept up to date by Microsoft (such as AzureKeyVault or Storage, with optional regional variants), that can be used as the source or destination in NSG rules.
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Azure NAT Gateway
Gives every resource in a subnet a managed way out to the internet through one or more fixed public IP addresses, while accepting no unsolicited inbound connections. Azure Container Apps can use it only when the environment is a workload profiles one.