Skip to content

Commit 60b2ed7

Browse files
committed
Added M2 tags
1 parent 5d44e56 commit 60b2ed7

File tree

1 file changed

+15
-3
lines changed

1 file changed

+15
-3
lines changed

articles/virtual-network/service-tags-overview.md

Lines changed: 15 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ ms.devlang: NA
1010
ms.topic: article
1111
ms.tgt_pltfrm: na
1212
ms.workload: infrastructure-services
13-
ms.date: 10/22/2019
13+
ms.date: 03/12/2020
1414
ms.author: jispar
1515
ms.reviewer: kumud
1616
---
@@ -37,8 +37,10 @@ By default, service tags reflect the ranges for the entire cloud. Some service t
3737

3838
| Tag | Purpose | Can use inbound or outbound? | Can be regional? | Can use with Azure Firewall? |
3939
| --- | -------- |:---:|:---:|:---:|:---:|:---:|:---:|:---:|
40+
| **ActionGroup** | Action Group. | Inbound | No | No |
4041
| **ApiManagement** | Management traffic for Azure API Management-dedicated deployments. <br/><br/>*Note:* This tag represents the Azure API Management service endpoint for control plane per region. This enables customers to perform management operations on the APIs, Operations, Policies, NamedValues configured on the API Management service. | Inbound | Yes | Yes |
4142
| **ApplicationInsightsAvailability** | Application Insights Availability. | Inbound | No | No |
43+
| **AppConfiguration** | App Configuration. | Outbound | No | No |
4244
| **AppService** | Azure App Service. This tag is recommended for outbound security rules to web app front ends. | Outbound | Yes | Yes |
4345
| **AppServiceManagement** | Management traffic for deployments dedicated to App Service Environment. | Both | No | Yes |
4446
| **AzureActiveDirectory** | Azure Active Directory. | Outbound | No | Yes |
@@ -54,36 +56,46 @@ By default, service tags reflect the ranges for the entire cloud. Some service t
5456
| **AzureDatabricks** | Azure Databricks. | Both | No | No |
5557
| **AzureDataExplorerManagement** | Azure Data Explorer Management. | Inbound | No | No |
5658
| **AzureDataLake** | Azure Data Lake Storage Gen1. | Outbound | No | Yes |
59+
| **AzureDevSpaces** | Azure Dev Spaces. | Outbound | No | No |
5760
| **AzureEventGrid** | Azure Event Grid. <br/><br/>*Note:* This tag covers Azure Event Grid endpoints in US South Central, US East, US East 2, US West 2, and US Central only. | Both | No | No |
58-
| **AzureFrontDoor** | Azure Front Door. | Both | No | No |
61+
| **AzureFrontDoor.Frontend** <br/> **AzureFrontDoor.Backend** <br/> **AzureFrontDoor.FirstParty** | Azure Front Door. | Both | No | No |
5962
| **AzureInformationProtection** | Azure Information Protection.<br/><br/>*Note:* This tag has a dependency on the **AzureActiveDirectory** and **AzureFrontDoor.Frontend** tags. Please also whitelist following IPs (this dependency will be removed soon): 13.107.6.181 & 13.107.9.181. | Outbound | No | No |
6063
| **AzureIoTHub** | Azure IoT Hub. | Outbound | No | No |
6164
| **AzureKeyVault** | Azure Key Vault.<br/><br/>*Note:* This tag has a dependency on the **AzureActiveDirectory** tag. | Outbound | Yes | Yes |
6265
| **AzureLoadBalancer** | The Azure infrastructure load balancer. The tag translates to the [virtual IP address of the host](security-overview.md#azure-platform-considerations) (168.63.129.16) where the Azure health probes originate. This does not include traffic to your Azure Load Balancer resource. If you're not using Azure Load Balancer, you can override this rule. | Both | No | No |
6366
| **AzureMachineLearning** | Azure Machine Learning. | Both | No | Yes |
6467
| **AzureMonitor** | Log Analytics, Application Insights, AzMon, and custom metrics (GiG endpoints).<br/><br/>*Note:* For Log Analytics, this tag has a dependency on the **Storage** tag. | Outbound | No | Yes |
68+
| **AzureOpenDatasets** | Azure Open Datasets. | Outbound | No | No |
6569
| **AzurePlatformDNS** | The basic infrastructure (default) DNS service.<br/><br>You can use this tag to disable the default DNS. Be cautious when you use this tag. We recommend that you read [Azure platform considerations](https://docs.microsoft.com/azure/virtual-network/security-overview#azure-platform-considerations). We also recommend that you perform testing before you use this tag. | Outbound | No | No |
6670
| **AzurePlatformIMDS** | Azure Instance Metadata Service (IMDS), which is a basic infrastructure service.<br/><br/>You can use this tag to disable the default IMDS. Be cautious when you use this tag. We recommend that you read [Azure platform considerations](https://docs.microsoft.com/azure/virtual-network/security-overview#azure-platform-considerations). We also recommend that you perform testing before you use this tag. | Outbound | No | No |
6771
| **AzurePlatformLKM** | Windows licensing or key management service.<br/><br/>You can use this tag to disable the defaults for licensing. Be cautious when you use this tag. We recommend that you read [Azure platform considerations](https://docs.microsoft.com/azure/virtual-network/security-overview#azure-platform-considerations). We also recommend that you perform testing before you use this tag. | Outbound | No | No |
6872
| **AzureResourceManager** | Azure Resource Manager. | Outbound | No | No |
69-
| **AzureSiteRecovery** | Azure Site Recovery.<br/><br/>*Note:* This tag has a dependency on the **Storage**, **AzureActiveDirectory**, and **EventHub** tags. | Outbound | No | No |
73+
| **AzureSignalR** | Azure SignalR. | Outbound | No | No |
74+
| **AzureSiteRecovery** | Azure Site Recovery.<br/><br/>*Note:* This tag has a dependency on the **AzureActiveDirectory**, **AzureKeyVault**, **EventHub**,**GuestAndHybridManagement** and **Storage** tags. | Outbound | No | No |
7075
| **AzureTrafficManager** | Azure Traffic Manager probe IP addresses.<br/><br/>For more information on Traffic Manager probe IP addresses, see [Azure Traffic Manager FAQ](https://docs.microsoft.com/azure/traffic-manager/traffic-manager-faqs). | Inbound | No | Yes |
7176
| **BatchNodeManagement** | Management traffic for deployments dedicated to Azure Batch. | Both | No | Yes |
7277
| **CognitiveServicesManagement** | The address ranges for traffic for Azure Cognitive Services. | Outbound | No | No |
78+
| **DataFactory** | Azure Data Factory | Outbound | No | No |
79+
| **DataFactoryManagement** | Management traffic for Azure Data Factory. | Inbound | No | No |
7380
| **Dynamics365ForMarketingEmail** | The address ranges for the marketing email service of Dynamics 365. | Outbound | Yes | No |
7481
| **ElasticAFD** | Elastic Azure Front Door. | Both | No | No |
7582
| **EventHub** | Azure Event Hubs. | Outbound | Yes | Yes |
7683
| **GatewayManager** | Management traffic for deployments dedicated to Azure VPN Gateway and Application Gateway. | Inbound | No | No |
7784
| **GuestAndHybridManagement** | Azure Automation and Guest Configuration. | Outbound | No | Yes |
7885
| **HDInsight** | Azure HDInsight. | Inbound | Yes | No |
7986
| **Internet** | The IP address space that's outside the virtual network and reachable by the public internet.<br/><br/>The address range includes the [Azure-owned public IP address space](https://www.microsoft.com/download/details.aspx?id=41653). | Both | No | No |
87+
| **LogicApps** | Logic Apps. | Outbound | No | No |
88+
| **LogicAppsManagement** | Management traffic for Logic Apps. | Inbound | No | No |
8089
| **MicrosoftCloudAppSecurity** | Microsoft Cloud App Security. | Outbound | No | No |
8190
| **MicrosoftContainerRegistry** | Container registry for Microsoft container images. <br/><br/>*Note:* Please also whitelist following IP (this dependency will be removed soon): 204.79.197.219. | Outbound | Yes | Yes |
91+
| **PowerQueryOnline** | Power Query Online. | Both | No | No |
8292
| **ServiceBus** | Azure Service Bus traffic that uses the Premium service tier. | Outbound | Yes | Yes |
8393
| **ServiceFabric** | Azure Service Fabric.<br/><br/>*Note:* This tag represents the Service Fabric service endpoint for control plane per region. This enables customers to perform management operations for their Service Fabric clusters from their VNET (endpoint eg. https:// westus.servicefabric.azure.com) | Both | No | No |
8494
| **Sql** | Azure SQL Database, Azure Database for MySQL, Azure Database for PostgreSQL, and Azure SQL Data Warehouse.<br/><br/>*Note:* This tag represents the service, but not specific instances of the service. For example, the tag represents the Azure SQL Database service, but not a specific SQL database or server. This tag does not apply to SQL managed instance. | Outbound | Yes | Yes |
8595
| **SqlManagement** | Management traffic for SQL-dedicated deployments. | Both | No | Yes |
8696
| **Storage** | Azure Storage. <br/><br/>*Note:* This tag represents the service, but not specific instances of the service. For example, the tag represents the Azure Storage service, but not a specific Azure Storage account. | Outbound | Yes | Yes |
97+
| **StorageSyncService** | Storage Sync Service. | Outbound | No | No |
98+
| **WindowsVirtualDesktop** | Windows Virtual Desktop. | Outbound | No | No |
8799
| **VirtualNetwork** | The virtual network address space (all IP address ranges defined for the virtual network), all connected on-premises address spaces, [peered](virtual-network-peering-overview.md) virtual networks, virtual networks connected to a [virtual network gateway](../vpn-gateway/vpn-gateway-about-vpngateways.md?toc=%2fazure%2fvirtual-network%3ftoc.json), the [virtual IP address of the host](security-overview.md#azure-platform-considerations), and address prefixes used on [user-defined routes](virtual-networks-udr-overview.md). This tag might also contain default routes. | Both | No | No |
88100

89101
>[!NOTE]

0 commit comments

Comments
 (0)