A set of IP prefixes for an Azure service, kept up to date by Microsoft (such as AzureKeyVault or Storage, with optional regional variants), that can be used as the source or destination in NSG rules.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Service tag in context, with comparison tables and the common traps.
Terms in this definition
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - Nonzonal
Describes a resource with no availability zone configuration. Azure can put it in any zone, so it may go offline if that zone fails.
- Default security rules
Built-in NSG rules at priorities 65000-65500: AllowVnetInBound, AllowAzureLoadBalancerInBound and DenyAllInBound, plus AllowVnetOutBound, AllowInternetOutBound and DenyAllOutBound. Removal is impossible; custom rules at 100-4096 take precedence.
Related terms
- Access restrictions
Allow and deny rules for inbound App Service traffic, matched on IP range, service tag or subnet. They can, for instance, restrict an app to a corporate NAT's public addresses.
- AllowVNetInBound
Built-in NSG inbound rule at priority 65000 that admits anything from the VirtualNetwork service tag, which also covers peered VNets.
- AzureCosmosDB (service tag)
Service tag covering Azure Cosmos DB's IP ranges, which can be scoped to a region and used as the destination of an outbound NSG rule.
- AzureFrontDoor.Backend
Service tag for the IP addresses Front Door uses when contacting origins. Pairing it with a filter on the X-Azure-FDID header in an access restriction ensures only your own Front Door instance gets through.
- AzureFrontDoor.FirstParty
Service tag that Microsoft reserves for its own Front Door-hosted services; locking down your origin is not what it is for.
- AzureFrontDoor.Frontend
Service tag covering the Front Door addresses that clients connect to, applied when controlling outbound traffic.
- AzureKeyVault (service tag)
Service tag, usable outbound and optionally regional, that represents the IP ranges of Azure Key Vault.
- AzureLoadBalancer (service tag)
Service tag standing for 168.63.129.16, which Azure's infrastructure load balancer uses as the source of its health probes; rules using it match probe traffic, never client requests.