How security admin rules are evaluated before NSGs, and when to use Allow, Deny or Always allow.
From Ultra Transcenders SC-500 by Tony Rough (publishing soon)
When the same control must apply to many virtual networks, editing NSGs one by one is slow and easy to undo locally. Azure Virtual Network Manager (AVNM) centralises connectivity and security configuration across a management scope.
| Security admin action | Effect |
|---|---|
| Allow | Passes traffic on to NSG evaluation |
| Deny | Blocks, regardless of NSGs |
| Always allow | Permits, regardless of NSGs |
| AVNM feature | Does |
|---|---|
| Connectivity configuration | Builds mesh (every VNet in a group connected bidirectionally) or hub-and-spoke; doesn’t filter |
| Security admin configuration | Central allow/deny rules evaluated before NSGs |
| Routing configuration | Steers traffic via next hops |
| IPAM | Allocates non-overlapping address space |
| Scope | Subscriptions/management groups the manager governs |
Common trap: Assuming internet traffic still reaches a VM because a lower-scope configuration or its NSG allows it - when a management-group-scoped manager applies a conflicting Deny, the higher scope wins and the traffic is blocked.
This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · Free SC-500 glossary · All SC-500 study notes
How PIM activation, approval, maximum duration and notifications work, and what each role setting controls.
How a Conditional Access policy is built and how multiple policies combine.
Why control-plane roles can't read secrets, and which Key Vault role or access policy each task needs.
What Deny, Audit, Append, Modify and DeployIfNotExists do, and when you need a remediation task and managed identity.
Account keys, account and service SAS, user delegation SAS and Entra RBAC compared by scope and revocability.
Where each Azure SQL data protection feature works and who it protects data from.
How JIT locks management ports and opens them on request, with the plan and permissions it needs.