You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|**ApiManagement**| Management traffic for Azure API Management-dedicated deployments. | Both | No | Yes |
41
+
|**ApplicationInsightsAvailability**| Application Insights Availability. | Both | No | No |
41
42
|**AppService**| Azure App Service. This tag is recommended for outbound security rules to web app front ends. | Outbound | Yes | Yes |
42
43
|**AppServiceManagement**| Management traffic for deployments dedicated to App Service Environment. | Both | No | Yes |
43
44
|**AzureActiveDirectory**| Azure Active Directory. | Outbound | No | Yes |
@@ -54,6 +55,8 @@ By default, service tags reflect the ranges for the entire cloud. Some service t
54
55
|**AzureDataExplorerManagement**| Azure Data Explorer Management. | Inbound | No | No |
55
56
|**AzureDataLake**| Azure Data Lake. | Outbound | No | Yes |
56
57
|**AzureEventGrid**| Azure Event Grid. <br/><br/>*Note:* This tag covers Azure Event Grid endpoints in US South Central, US East, US East 2, US West 2, and US Central only. | Both | No | No |
58
+
|**AzureFrontDoor**| Azure Front Door. | Both | No | No |
59
+
|**AzureInformationProtection**| Azure Information Protection.<br/><br/>*Note:* This tag has a dependency on the **AzureFrontDoor** tag. | Outbound | No | No |
57
60
|**AzureIoTHub**| Azure IoT Hub. | Outbound | No | No |
58
61
|**AzureKeyVault**| Azure Key Vault.<br/><br/>*Note:* This tag has a dependency on the **AzureActiveDirectory** tag. | Outbound | Yes | Yes |
59
62
|**AzureLoadBalancer**| The Azure infrastructure load balancer. The tag translates to the [virtual IP address of the host](security-overview.md#azure-platform-considerations) (168.63.129.16) where the Azure health probes originate. If you're not using Azure Load Balancer, you can override this rule. | Both | No | No |
@@ -63,14 +66,18 @@ By default, service tags reflect the ranges for the entire cloud. Some service t
63
66
|**AzurePlatformIMDS**| Azure Instance Metadata Service (IMDS), which is a basic infrastructure service.<br/><br/>You can use this tag to disable the default IMDS. Be cautious when you use this tag. We recommend that you read [Azure platform considerations](https://docs.microsoft.com/azure/virtual-network/security-overview#azure-platform-considerations). We also recommend that you perform testing before you use this tag. | Outbound | No | No |
64
67
|**AzurePlatformLKM**| Windows licensing or key management service.<br/><br/>You can use this tag to disable the defaults for licensing. Be cautious when you use this tag. We recommend that you read [Azure platform considerations](https://docs.microsoft.com/azure/virtual-network/security-overview#azure-platform-considerations). We also recommend that you perform testing before you use this tag. | Outbound | No | No |
65
68
|**AzureResourceManager**| Azure Resource Manager. | Outbound | No | No |
69
+
|**AzureSiteRecovery**| Azure Site Recovery.<br/><br/>*Note:* This tag has a dependency on the **Storage**, **AzureActiveDirectory**, and **EventHub** tags. | Outbound | No | No |
66
70
|**AzureTrafficManager**| Azure Traffic Manager probe IP addresses.<br/><br/>For more information on Traffic Manager probe IP addresses, see [Azure Traffic Manager FAQ](https://docs.microsoft.com/azure/traffic-manager/traffic-manager-faqs). | Inbound | No | Yes |
67
71
|**BatchNodeManagement**| Management traffic for deployments dedicated to Azure Batch. | Both | No | Yes |
68
72
|**CognitiveServicesManagement**| The address ranges for traffic for Azure Cognitive Services. | Outbound | No | No |
69
73
|**Dynamics365ForMarketingEmail**| The address ranges for the marketing email service of Dynamics 365. | Outbound | Yes | No |
74
+
|**ElasticAFD**| Elastic Azure Front Door. | Both | No | No |
|**GatewayManager**| Management traffic for deployments dedicated to Azure VPN Gateway and Application Gateway. | Inbound | No | No |
77
+
|**GuestAndHybridManagement**| Azure Automation and Guest Configuration. | Both | No | Yes |
72
78
|**HDInsight**| Azure HDInsight. | Inbound | Yes | No |
73
79
|**Internet**| The IP address space that's outside the virtual network and reachable by the public internet.<br/><br/>The address range includes the [Azure-owned public IP address space](https://www.microsoft.com/download/details.aspx?id=41653). | Both | No | No |
80
+
|**MicrosoftCloudAppSecurity**| Microsoft Cloud App Security. | Outbound | No | No |
0 commit comments