Built-in NSG rules at priorities 65000-65500: AllowVnetInBound, AllowAzureLoadBalancerInBound and DenyAllInBound, plus AllowVnetOutBound, AllowInternetOutBound and DenyAllOutBound. Removal is impossible; custom rules at 100-4096 take precedence.
Also called NSG.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Default security rules in context, with comparison tables and the common traps.
Terms in this definition
- AllowVNetInBound
Built-in NSG inbound rule at priority 65000 that admits anything from the VirtualNetwork service tag, which also covers peered VNets.
- AllowAzureLoadBalancerInBound
Built-in NSG inbound rule at priority 65001 that admits traffic coming from Azure Load Balancer, health probes included.
- DenyAllInBound
The priority-65500 default NSG rule that drops any inbound traffic, internet included, which no earlier rule has allowed.
- AllowVnetOutBound
Built-in NSG outbound rule at priority 65000 that lets VMs open connections towards their own VNet and peered VNets. The NSG at the destination still has to permit the port.
- AllowInternetOutBound
Built-in NSG outbound rule at priority 65001 that lets traffic reach the internet. A deny rule with a smaller priority number overrides it.
Related terms
- Application security group
Named collection of VM NICs that NSG rules can use as source or destination in place of IP addresses. NICs join only when explicitly added, and they must all belong to one VNet.
- Azure Instance Metadata Service
Endpoint at the non-routable address 169.254.169.254, reachable only from within a VM, that returns metadata about the VM and issues managed identity tokens. An outbound NSG rule denying the AzurePlatformIMDS tag cuts off access.
- AzureCosmosDB (service tag)
Service tag covering Azure Cosmos DB's IP ranges, which can be scoped to a region and used as the destination of an outbound NSG rule.
- AzureNetworkAnalytics_CL
Table in Log Analytics populated by Traffic Analytics with processed NSG flow log results; each field name ends with a type suffix, for example
FlowType_s,SubType_sorFlowStartTime_t. - AzurePlatformIMDS (service tag)
Service tag for the Instance Metadata Service at 169.254.169.254, meaningful only outbound. Denying it in an outbound NSG rule stops the VM reaching IMDS; inbound rules using it do nothing.
- Connection troubleshoot
One-time Network Watcher check from a VM to another VM, an FQDN, a URI or an IP and port, reporting whether it is reachable, the latency and which hop (route or NSG) breaks it.
- Effective security rules
Network Watcher feature showing the merged subnet and NIC NSG rules that apply to a network interface; it does not test any traffic.
- GatewayManager (service tag)
Represents the management traffic Azure's own infrastructure sends. On an Application Gateway v2 subnet, the NSG has to let this tag in on ports 65200-65535 (65503-65534 for v1).