A firewall rule on resources such as Storage or Foundry Tools that lets in one subnet, provided the subnet has the corresponding service endpoint. The rule matters only with a default action of Deny; enabling the endpoint by itself allows nothing.
Also called VNet rule.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Virtual network rule in context, with comparison tables and the common traps.
Terms in this definition
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - Foundry Tools
Microsoft's collection of AI APIs that can be used ready-made or customised, spanning areas such as Vision, Speech, Language, Document Intelligence, Content Safety and Content Understanding.
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
- Service endpoint
Sends a subnet's traffic to an Azure service's public endpoint across the Microsoft backbone, identifying the subnet as the source. It is free, uses no subnet IP addresses and cannot be used from on-premises networks.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
Related terms
- Server IP firewall rules
Rules on an Azure SQL logical server that permit ranges of public source IPs. Private VNet addresses never match them; those require a virtual network rule.