A rule from Azure Virtual Network Manager that takes effect ahead of NSG rules. Its action is Deny (blocks whatever NSGs say), Always allow (bypasses NSGs) or Allow (hands traffic on for NSG evaluation).
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Security admin rule in context, with comparison tables and the common traps.
Terms in this definition
- Azure Virtual Network Manager
Service for centrally managing connectivity, as hub-and-spoke or mesh, and security admin rules across VNets in many subscriptions. VNets in other tenants must be added as static members, because dynamic membership driven by Azure Policy works only within one tenant.
- Default security rules
Built-in NSG rules at priorities 65000-65500: AllowVnetInBound, AllowAzureLoadBalancerInBound and DenyAllInBound, plus AllowVnetOutBound, AllowInternetOutBound and DenyAllOutBound. Removal is impossible; custom rules at 100-4096 take precedence.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
Related terms
- NSG diagnostics
Tests a simulated flow against each applicable Virtual Network Manager security admin rule and NSG rule, then gives allow or deny with the deciding rule. Scale sets and ICMP are supported.