This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure storage, databases, and networking (25–30%)
--> Implement security for Azure network services
--> Implement and manage network security groups (NSGs) and application security groups (ASGs)
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Network security groups (NSGs) and application security groups (ASGs) are foundational Azure networking features used to control traffic within and between Azure virtual networks.
- Network security groups provide traffic filtering through inbound and outbound security rules.
- Application security groups allow administrators to organize virtual machines and network interfaces according to application roles rather than relying on individual IP addresses.
Together, NSGs and ASGs support defense in depth, network segmentation, least-privilege access, and easier security-rule management.
An NSG can be associated with:
- A subnet
- A network interface card (NIC)
- Both a subnet and a NIC
When an NSG is associated with a subnet, its rules apply to the resources in that subnet. When it is associated with a NIC, its rules apply to the traffic for that network interface.
1. Understand Network Security Groups
A network security group is an Azure resource containing security rules that allow or deny network traffic.
Each rule can evaluate traffic based on:
- Source
- Source port
- Destination
- Destination port
- Protocol
- Direction
- Priority
- Action
Supported protocols include:
- TCP
- UDP
- Any
The action is either:
- Allow
- Deny
For example, an NSG rule could allow HTTPS traffic from the Internet to a web server while denying direct inbound access to the database tier.
Example security rule
| Property | Example |
|---|---|
| Name | Allow-HTTPS |
| Direction | Inbound |
| Priority | 100 |
| Source | Internet |
| Source port | * |
| Destination | Web server subnet |
| Destination port | 443 |
| Protocol | TCP |
| Action | Allow |
A lower priority number has higher precedence. For example, priority 100 is evaluated before priority 200.
2. NSG Default Rules
Every NSG contains default security rules. These rules cannot be deleted, but custom rules can override them by using a higher priority.
Common default inbound rules include:
- Allow traffic from the
VirtualNetworkservice tag - Allow traffic from the
AzureLoadBalancerservice tag - Deny all other inbound traffic
Common default outbound rules include:
- Allow traffic to the
VirtualNetworkservice tag - Allow traffic to the Internet
- Deny all other outbound traffic
The default rules are evaluated after custom rules. Therefore, a custom rule with a priority lower than the default deny rule can allow traffic that would otherwise be denied.
Important exam point
NSGs are not automatically “deny all” in every direction. They include default rules that permit certain virtual-network and outbound Internet traffic. Security administrators should explicitly review and override these defaults when stricter controls are required.
3. Inbound and Outbound Rule Evaluation
NSGs filter both inbound and outbound traffic.
Inbound traffic
For a virtual machine with NSGs at both the subnet and NIC levels:
- Azure evaluates the subnet-level NSG.
- Azure evaluates the NIC-level NSG.
- Traffic must be allowed by both NSGs.
Outbound traffic
For outbound traffic:
- Azure evaluates the NIC-level NSG.
- Azure evaluates the subnet-level NSG.
- Traffic must be allowed by both NSGs.
The effective result is the combined set of applicable rules. A deny rule in either NSG can prevent traffic from flowing.
Example
Suppose:
- The subnet NSG allows inbound TCP 443.
- The NIC NSG denies inbound TCP 443.
The traffic is denied because both NSGs must permit the traffic.
Similarly:
- The subnet NSG allows outbound TCP 1433.
- The NIC NSG denies outbound TCP 1433.
The connection is denied.
4. NSG Rule Priority
Each custom NSG rule must have a unique priority number.
- Lower numbers have higher priority.
- Rules are evaluated in priority order.
- Evaluation stops when a matching rule is found.
- A later rule cannot override an earlier matching rule.
Example
| Priority | Rule | Action |
|---|---|---|
| 100 | Allow TCP 443 from Internet | Allow |
| 110 | Deny all inbound traffic | Deny |
HTTPS traffic is allowed because the priority 100 rule is evaluated first.
If the rules were reversed:
| Priority | Rule | Action |
|---|---|---|
| 100 | Deny all inbound traffic | Deny |
| 110 | Allow TCP 443 from Internet | Allow |
The HTTPS allow rule would never be reached for matching traffic.
Best practices
- Reserve priority ranges for different application tiers.
- Use descriptive rule names.
- Avoid overlapping rules.
- Place specific rules before broad rules.
- Avoid using unnecessarily permissive rules such as
Anyfor both source and destination. - Document why each rule exists.
5. Source and Destination Options
NSG rules can use several types of source and destination values.
Any
Matches all addresses.
Use this only when broad access is intentionally required.
IP addresses or CIDR ranges
You can specify:
- A single IP address
- Multiple IP addresses
- A subnet range
- Multiple CIDR ranges
Example:
10.10.1.0/24
Service tags
A service tag represents a group of IP address prefixes associated with an Azure service or category of traffic.
Examples include:
VirtualNetworkInternetAzureLoadBalancerAzureCloudStorageAzureKeyVault
Microsoft maintains the IP prefixes represented by service tags and updates them as Azure addresses change. This avoids manually maintaining large lists of IP addresses.
Application security groups
An ASG can be used as the source or destination of an NSG rule. This allows rules to be based on application roles instead of IP addresses.
For example:
Source ASG: Asg-WebDestination ASG: Asg-DatabaseDestination port: 1433Protocol: TCPAction: Allow
This rule allows members of the web application group to communicate with members of the database group over TCP port 1433.
6. Network Security Group Association
An NSG can be associated with a subnet, a NIC, or both.
Subnet-level association
A subnet-level NSG is useful when a common policy should apply to all resources in the subnet.
Examples:
- Deny inbound Internet traffic to a private application subnet.
- Allow communication from a shared management subnet.
- Restrict outbound traffic from a database subnet.
NIC-level association
A NIC-level NSG is useful when a particular virtual machine requires additional controls beyond the subnet policy.
Examples:
- A management server requires SSH access.
- A specific application server needs an additional inbound port.
- A sensitive VM requires stricter outbound restrictions.
Recommended design
Use subnet-level NSGs for broad segmentation and NIC-level NSGs for workload-specific restrictions. Avoid creating unnecessarily complicated combinations that are difficult to troubleshoot.
7. Understand Application Security Groups
An application security group is a logical grouping of network interfaces.
ASGs allow administrators to define security rules according to application architecture, such as:
- Web servers
- Application servers
- Database servers
- Management servers
- Monitoring servers
Instead of creating rules based on individual IP addresses, you can create rules based on group membership.
Example application groups
Asg-WebAsg-AppAsg-DatabaseAsg-Management
A rule could allow:
Asg-Web → Asg-App → TCP 8080Asg-App → Asg-Database → TCP 1433Asg-Management → Asg-Web → TCP 22
This design is easier to maintain when virtual machines are added, removed, or assigned new IP addresses.
ASGs are logical groupings; they do not themselves filter traffic. The filtering is performed by NSG rules that reference the ASGs.
8. ASG Constraints
Important ASG constraints include:
- An ASG contains network interfaces, not entire virtual machines directly.
- All NICs in an ASG must be in the same virtual network.
- An ASG cannot contain NICs from different virtual networks.
- If an NSG rule uses an ASG as both source and destination, the referenced ASGs must contain NICs in the same virtual network.
- A NIC can belong to multiple ASGs.
- An ASG does not automatically grant access; a matching NSG rule is still required.
The location and virtual-network requirements should be considered when designing application groups.
9. ASGs and Dynamic Application Membership
ASGs are especially useful when application membership changes frequently.
For example, an organization may have:
- Three web servers today
- Six web servers next month
- Different private IP addresses after redeployment
If the web server NICs are members of Asg-Web, the NSG rule can remain unchanged as servers are added or removed.
The administrator only needs to update ASG membership.
Benefits
- Reduces dependence on hard-coded IP addresses
- Simplifies rule maintenance
- Supports application-centric segmentation
- Makes security intent easier to understand
- Reduces the number of rules required
- Helps maintain consistent policies during scaling
Microsoft recommends using ASGs and service tags where appropriate to reduce rule complexity.
10. Example Three-Tier Application Design
Consider a three-tier application:
Internet | vWeb tier | vApplication tier | vDatabase tier
Create the following ASGs:
Asg-WebAsg-AppAsg-Database
Then configure NSG rules such as:
| Priority | Source | Destination | Port | Action |
|---|---|---|---|---|
| 100 | Internet | Asg-Web | 443 | Allow |
| 110 | Asg-Web | Asg-App | 8080 | Allow |
| 120 | Asg-App | Asg-Database | 1433 | Allow |
| 130 | Asg-Management | Asg-Web | 22 | Allow |
| 4000 | Any | Any | Any | Deny |
This approach prevents direct Internet access to the application and database tiers.
The database tier does not need to allow traffic from the entire virtual network. It only needs to allow traffic from the application tier on the required port.
11. Service Tags Versus ASGs
Service tags and ASGs solve different problems.
| Feature | Service tags | Application security groups |
|---|---|---|
| Represents | Azure service IP ranges or traffic categories | Application network interfaces |
| Example | Storage, Internet, AzureLoadBalancer | Asg-Web, Asg-Database |
| Main purpose | Simplify access to Azure services | Simplify application segmentation |
| Managed by | Microsoft-managed IP prefix updates | Customer-managed membership |
| Common use | Allow traffic from Azure Storage | Allow web servers to access database servers |
Use service tags when the source or destination is an Azure service or well-defined traffic category. Use ASGs when the source or destination is a group of application workloads.
12. Augmented Security Rules
Augmented security rules allow multiple values to be specified in a single rule.
For example, one rule can contain:
- Multiple source IP addresses
- Multiple destination IP addresses
- Multiple ports
- Port ranges
This can reduce the number of individual rules required.
Example:
Source ports: *Destination ports: 80, 443, 8080Protocol: TCPAction: Allow
Augmented rules should be used carefully. Combining unrelated access requirements into one rule can make the security policy harder to understand. Where possible, use service tags and ASGs to express the security intent more clearly.
13. Managing NSGs and ASGs
NSGs and ASGs can be managed through:
- Azure portal
- Azure PowerShell
- Azure CLI
- Azure Resource Manager templates
- Bicep
- Terraform
Typical management tasks include:
- Create an NSG.
- Create an ASG.
- Associate the NSG with a subnet or NIC.
- Add NICs to the ASG.
- Create inbound and outbound rules.
- Test connectivity.
- Review effective security rules.
- Update or remove obsolete rules.
Azure CLI examples
Create an NSG:
az network nsg create \ --resource-group NetworkRG \ --name nsg-web
Create an ASG:
az network asg create \ --resource-group NetworkRG \ --name asg-web \ --location eastus
Create an inbound rule allowing HTTPS to the web ASG:
az network nsg rule create \ --resource-group NetworkRG \ --nsg-name nsg-web \ --name Allow-HTTPS \ --access Allow \ --protocol Tcp \ --direction Inbound \ --priority 100 \ --source-address-prefix Internet \ --source-port-range "*" \ --destination-asgs asg-web \ --destination-port-range 443
The exact command syntax can vary depending on whether the rule references IP addresses, service tags, or ASGs.
14. Troubleshooting NSG Connectivity
When traffic is unexpectedly blocked, review the following:
1. Confirm the destination port
Ensure the application is actually listening on the expected port.
2. Confirm the source address
The source may be:
- A private IP address
- A public IP address
- A load balancer
- A service tag
- Another application group
A rule that allows the wrong source range will not match.
3. Check both NSGs
Review:
- The subnet-level NSG
- The NIC-level NSG
A deny rule in either NSG can block traffic.
4. Review effective security rules
Effective security rules show the aggregated rules applied to a NIC, including rules from both the subnet and NIC NSGs.
In the Azure portal, effective rules can be viewed from the VM’s networking settings. They can also be retrieved with Azure CLI:
az network nic list-effective-nsg \ --name vm-nic \ --resource-group NetworkRG
This is one of the most important troubleshooting tools for NSG-related connectivity problems.
5. Check rule priority
A broad deny rule with a higher priority can prevent a later allow rule from being evaluated.
6. Check ASG membership
If an NSG rule references an ASG, verify that the destination or source NIC is actually a member of that ASG.
7. Check other networking controls
NSGs are not the only possible cause of blocked traffic. Also consider:
- Azure Firewall
- Network virtual appliances
- Route tables
- Private endpoints
- Application Gateway
- Operating-system firewalls
- Application configuration
- Network Watcher connection troubleshooting
15. NSGs Are Not a Replacement for Azure Firewall
NSGs provide basic network traffic filtering at the subnet and NIC levels. They are not a full network firewall solution.
NSGs generally do not provide the same capabilities as Azure Firewall, such as:
- Centralized stateful inspection
- Advanced threat intelligence filtering
- Intrusion detection and prevention
- Centralized application and network rule processing
- Advanced logging and security operations integration
A common defense-in-depth architecture uses:
- NSGs for subnet and workload segmentation
- Azure Firewall for centralized traffic inspection
- Application Gateway WAF for web application protection
- Private Link for private access to PaaS services
- Microsoft Defender for Cloud for security posture management
16. Best Practices
Use least privilege
Allow only the required:
- Sources
- Destinations
- Ports
- Protocols
- Directions
Prefer application-based rules
Use ASGs instead of individual IP addresses when controlling communication between application tiers.
Use service tags appropriately
Use service tags to avoid maintaining changing Azure service IP ranges manually.
Avoid unrestricted access
Avoid rules that allow:
Source: AnyDestination: AnyPort: AnyProtocol: AnyAction: Allow
unless there is a documented and justified requirement.
Separate application tiers
Use different subnets and ASGs for:
- Web
- Application
- Database
- Management
Review effective rules
Regularly inspect effective security rules to verify that the actual applied policy matches the intended design.
Use infrastructure as code
Define NSGs, ASGs, and rules in Bicep, ARM templates, or another approved infrastructure-as-code solution to improve consistency and auditability.
Remove obsolete rules
Unused rules increase complexity and may create unintended access paths.
Document security intent
Use descriptive names and descriptions such as:
Allow-App-to-Database-SQL
rather than:
Rule1
Practice Exam Questions
Question 1
A company hosts a three-tier application in Azure. Web servers must communicate with application servers over TCP port 8080. Application servers must communicate with database servers over TCP port 1433. The company wants security rules to remain valid when virtual machines are added or their private IP addresses change.
What should you implement?
A. Create ASGs for each application tier and reference them in NSG rules.
B. Create a separate NSG for every virtual machine using static IP addresses.
C. Allow all traffic between the application subnets.
D. Use public IP addresses for all application servers.
Correct answer: A
Explanation: ASGs allow NSG rules to reference application roles instead of individual IP addresses. Membership can change without requiring the security rules to be rewritten.
Question 2
An NSG associated with a subnet allows inbound TCP port 443. An NSG associated with a VM’s NIC denies inbound TCP port 443 from the same source.
What is the result?
A. The subnet NSG takes precedence, so traffic is allowed.
B. The NIC NSG takes precedence, so traffic is denied.
C. Azure randomly selects one of the rules.
D. The traffic is allowed only if the VM has a public IP address.
Correct answer: B
Explanation: Both the subnet-level and NIC-level NSGs apply. Traffic must be allowed by both. The deny rule in the NIC-level NSG blocks the connection.
Question 3
An administrator creates an NSG rule with priority 100 that denies all inbound traffic. Another rule with priority 200 allows inbound HTTPS traffic.
What happens to inbound HTTPS traffic?
A. HTTPS is allowed because it uses a secure protocol.
B. HTTPS is allowed because the allow rule is more specific.
C. HTTPS is denied because the priority 100 rule is evaluated first.
D. Azure combines the actions and allows the traffic.
Correct answer: C
Explanation: Lower priority numbers are evaluated first. The broad deny rule at priority 100 matches the traffic, so the later allow rule is not evaluated.
Question 4
A VM cannot receive traffic from another VM in the same virtual network. The NSG associated with the destination NIC allows the traffic, but the subnet-level NSG contains a deny rule.
What should the administrator do first?
A. Assign a public IP address to the destination VM.
B. Review and modify the subnet-level NSG rule.
C. Disable the destination VM’s operating-system firewall.
D. Create an Azure Firewall policy.
Correct answer: B
Explanation: Both the subnet-level and NIC-level NSGs apply. A deny rule at the subnet level can block traffic even when the NIC-level NSG allows it.
Question 5
An organization wants to allow traffic from Azure Storage without manually maintaining a list of changing Azure IP addresses.
Which feature should be used?
A. Application security group
B. User-defined route
C. Service tag
D. Public IP prefix
Correct answer: C
Explanation: Service tags represent Microsoft-managed groups of IP address prefixes for Azure services. Microsoft updates the prefixes as service addresses change.
Question 6
A security administrator creates an ASG named Asg-Database. The administrator then creates an NSG rule allowing traffic to Asg-Database on TCP port 1433.
A database VM is not receiving the traffic.
Which issue could explain the problem?
A. The VM’s NIC is not a member of Asg-Database.
B. ASGs automatically deny all traffic.
C. ASGs can contain only public IP addresses.
D. ASGs work only with Azure Firewall.
Correct answer: A
Explanation: An NSG rule referencing an ASG applies only to network interfaces that are members of that ASG. The ASG itself does not automatically include every VM in a subnet.
Question 7
Which statement about application security groups is correct?
A. An ASG directly filters traffic without an NSG.
B. An ASG can contain NICs from multiple virtual networks.
C. An ASG is a logical grouping of network interfaces used by NSG rules.
D. An ASG replaces the need for subnet-level NSGs.
Correct answer: C
Explanation: ASGs provide logical grouping. NSG rules perform the actual allow or deny operation. NICs in an ASG must be in the same virtual network.
Question 8
A VM cannot connect to a database server. The administrator wants to see the combined inbound and outbound rules applied from the subnet and NIC NSGs.
Which feature should be used?
A. Azure Advisor
B. Effective security rules
C. Microsoft Defender Vulnerability Management
D. Azure Service Health
Correct answer: B
Explanation: Effective security rules show the aggregated rules applied to a network interface and are designed to help troubleshoot NSG-related connectivity issues.
Question 9
A company wants to allow management traffic only from a management subnet to selected application servers. The application servers are distributed across several subnets in the same virtual network.
What is the most maintainable approach?
A. Add every application server’s private IP address to a separate rule.
B. Allow management traffic from the entire virtual network to every server.
C. Create an ASG for the management servers and an ASG for the target application servers, then reference them in an NSG rule.
D. Assign public IP addresses to the management servers.
Correct answer: C
Explanation: ASGs allow security policies to be expressed according to application roles. The rule can remain stable as servers are added or their IP addresses change.
Question 10
An administrator wants to create a rule that allows TCP ports 80, 443, and 8080 from a specified source range using one NSG rule.
Which NSG capability supports this configuration?
A. Augmented security rules
B. Azure Bastion
C. Application Gateway WAF
D. Private Link
Correct answer: A
Explanation: Augmented security rules allow multiple ports, addresses, and ranges to be specified in a single rule, reducing the number of individual rules required.
Final Exam Point
NSGs and ASGs are most effective when used together: NSGs enforce traffic rules, while ASGs make those rules easier to express and maintain according to application architecture.
Go to the SC-500 Exam Prep Hub main page
