Azure service tags overview (2023)

ActionGroupAction Group.InboundNoNoApiManagementManagement traffic for Azure API Management-dedicated deployments.

Note: This tag represents the Azure API Management service endpoint for control plane per region. The tag enables customers to perform management operations on the APIs, Operations, Policies, NamedValues configured on the API Management service.

InboundYesYesApplicationInsightsAvailabilityApplication Insights Availability.InboundNoNoAppConfigurationApp Configuration.OutboundNoNoAppServiceAzure App Service. This tag is recommended for outbound security rules to web apps and Function apps.

Note: This tag doesn't include IP addresses assigned when using IP-based SSL (App-assigned address).

OutboundYesYesAppServiceManagementManagement traffic for deployments dedicated to App Service Environment.BothNoYesAutonomousDevelopmentPlatformAutonomous Development PlatformBothYesNoAzureActiveDirectoryAzure Active Directory.OutboundNoYesAzureActiveDirectoryDomainServicesManagement traffic for deployments dedicated to Azure Active Directory Domain Services.BothNoYesAzureAdvancedThreatProtectionAzure Advanced Threat Protection.OutboundNoNoAzureArcInfrastructureAzure Arc-enabled servers, Azure Arc-enabled Kubernetes, and Guest Configuration traffic.

Note: This tag has a dependency on the AzureActiveDirectory,AzureTrafficManager, and AzureResourceManager tags.

OutboundNoYesAzureAttestationAzure Attestation.OutboundNoYesAzureBackupAzure Backup.

Note: This tag has a dependency on the Storage and AzureActiveDirectory tags.

OutboundNoYesAzureBotServiceAzure Bot Service.OutboundNoNoAzureCloudAll datacenter public IP addresses.BothYesYesAzureCognitiveSearchAzure Cognitive Search.

This tag or the IP addresses covered by this tag can be used to grant indexers secure access to data sources. For more information about indexers, see indexer connection documentation.

(Video) What is NSG Service Tag? What is Azure Service Tag?

Note: The IP of the search service isn't included in the list of IP ranges for this service tag and also needs to be added to the IP firewall of data sources.

InboundNoNoAzureConnectorsThis tag represents the IP addresses used for managed connectors that make inbound webhook callbacks to the Azure Logic Apps service and outbound calls to their respective services, for example, Azure Storage or Azure Event Hubs.BothYesYesAzureContainerAppsServiceAzure Container Apps ServiceBothYesNoAzureContainerRegistryAzure Container Registry.OutboundYesYesAzureCosmosDBAzure Cosmos DB.OutboundYesYesAzureDatabricksAzure Databricks.BothNoNoAzureDataExplorerManagementAzure Data Explorer Management.InboundNoNoAzureDataLakeAzure Data Lake Storage Gen1.OutboundNoYesAzureDeviceUpdateDevice Update for IoT Hub.BothNoYesAzureDevSpacesAzure Dev Spaces.OutboundNoNoAzureDevOpsAzure DevOps.InboundYesYesAzureDigitalTwinsAzure Digital Twins.

Note: This tag or the IP addresses covered by this tag can be used to restrict access to endpoints configured for event routes.

InboundNoYesAzureEventGridAzure Event Grid.BothNoNoAzureFrontDoor.Frontend
AzureFrontDoor.Backend
AzureFrontDoor.FirstPartyAzure Front Door.BothYesYesAzureHealthcareAPIsThe IP addresses covered by this tag can be used to restrict access to Azure Health Data Services.BothNoYesAzureInformationProtectionAzure Information Protection.

Note: This tag has a dependency on the AzureActiveDirectory, AzureFrontDoor.Frontend and AzureFrontDoor.FirstParty tags.

OutboundNoNoAzureIoTHubAzure IoT Hub.OutboundYesNoAzureKeyVaultAzure Key Vault.

Note: This tag has a dependency on the AzureActiveDirectory tag.

OutboundYesYesAzureLoadBalancerThe Azure infrastructure load balancer. The tag translates to the virtual IP address of the host (168.63.129.16) where the Azure health probes originate. This only includes probe traffic, not real traffic to your backend resource. If you're not using Azure Load Balancer, you can override this rule.BothNoNoAzureLoadTestingInstanceManagementThis service tag is used for inbound connectivity from Azure Load Testing service to the load generation instances injected into your virtual network in the private load testing scenario.

Note: This tag is intended to be used in Azure Firewall, NSG, UDR and all other gateways for inbound connectivity.

(Video) Azure Service Tags | How to Use

NoYesAzureMachineLearningAzure Machine Learning.BothNoYesAzureMonitorLog Analytics, Application Insights, AzMon, and custom metrics (GiG endpoints).

Note: For Log Analytics, the Storage tag is also required. If Linux agents are used, GuestAndHybridManagement tag is also required.

OutboundNoYesAzureOpenDatasetsAzure Open Datasets.

Note: This tag has a dependency on the AzureFrontDoor.Frontend and Storage tag.

OutboundNoNoAzurePlatformDNSThe basic infrastructure (default) DNS service.

You can use this tag to disable the default DNS. Be cautious when you use this tag. We recommend that you read Azure platform considerations. We also recommend that you perform testing before you use this tag.

OutboundNoNoAzurePlatformIMDSAzure Instance Metadata Service (IMDS), which is a basic infrastructure service.

You can use this tag to disable the default IMDS. Be cautious when you use this tag. We recommend that you read Azure platform considerations. We also recommend that you perform testing before you use this tag.

OutboundNoNoAzurePlatformLKMWindows licensing or key management service.

You can use this tag to disable the defaults for licensing. Be cautious when you use this tag. We recommend that you read Azure platform considerations. We also recommend that you perform testing before you use this tag.

(Video) Azure Service Tags for User-Defined Routes (UDR)

OutboundNoNoAzureResourceManagerAzure Resource Manager.OutboundNoNoAzureSentinelMicrosoft Sentinel.InboundYesYesAzureSignalRAzure SignalR.OutboundNoNoAzureSiteRecoveryAzure Site Recovery.

Note: This tag has a dependency on the AzureActiveDirectory, AzureKeyVault, EventHub,GuestAndHybridManagement and Storage tags.

OutboundNoNoAzureSphereThis tag or the IP addresses covered by this tag can be used to restrict access to Azure Sphere Security Services.BothNoYesAzureStackAzure Stack Bridge services. This tag represents the Azure Stack Bridge service endpoint per region.OutboundNoYesAzureTrafficManagerAzure Traffic Manager probe IP addresses.

For more information on Traffic Manager probe IP addresses, see Azure Traffic Manager FAQ.

InboundNoYesAzureUpdateDeliveryFor accessing Windows Updates.

Note: This tag provides access to Windows Update metadata services. To successfully download updates, you must also enable the AzureFrontDoor.FirstParty service tag and configure outbound security rules with the protocol and port defined as follows:

  • AzureUpdateDelivery: TCP, port 443
  • AzureFrontDoor.FirstParty: TCP, port 80
OutboundNoNoAzureWebPubSubAzureWebPubSubBothYesNoBatchNodeManagementManagement traffic for deployments dedicated to Azure Batch.BothYesYesChaosStudioAzure Chaos Studio.

Note: If you have enabled Application Insights integration on the Chaos Agent, the AzureMonitor tag is also required.

BothYesNoCognitiveServicesManagementThe address ranges for traffic for Azure Cognitive Services.BothNoNoDataFactoryAzure Data FactoryBothNoNoDataFactoryManagementManagement traffic for Azure Data Factory.OutboundNoNoDynamics365ForMarketingEmailThe address ranges for the marketing email service of Dynamics 365.OutboundYesNoDynamics365BusinessCentralThis tag or the IP addresses covered by this tag can be used to restrict access from/to the Dynamics 365 Business Central Services.BothNoYesEOPExternalPublishedIPsThis tag represents the IP addresses used for Security & Compliance Center PowerShell. Refer to the .BothNoYesEventHubAzure Event Hubs.OutboundYesYesGatewayManagerManagement traffic for deployments dedicated to Azure VPN Gateway and Application Gateway.InboundNoNoGuestAndHybridManagementAzure Automation and Guest Configuration.OutboundNoYesHDInsightAzure HDInsight.InboundYesNoInternetThe IP address space that's outside the virtual network and reachable by the public internet.

The address range includes the Azure-owned public IP address space.

(Video) Azure Virtual Network and PaaS Network Controls

BothNoNoLogicAppsLogic Apps.BothNoNoLogicAppsManagementManagement traffic for Logic Apps.InboundNoNoM365ManagementActivityApiThe Office 365 Management Activity API provides information about various user, admin, system, and policy actions and events from Office 365 and Azure Active Directory activity logs. Customers and partners can use this information to create new or enhance existing operations, security, and compliance-monitoring solutions for the enterprise.

Note: This tag has a dependency on the AzureActiveDirectory tag.

OutboundYesNoM365ManagementActivityApiWebhookNotifications are sent to the configured webhook for a subscription as new content becomes available.InboundYesNoMicrosoftAzureFluidRelayThis tag represents the IP addresses used for Azure Microsoft Fluid Relay Server.OutboundNoNoMicrosoftCloudAppSecurityMicrosoft Defender for Cloud Apps.OutboundNoNoMicrosoftContainerRegistryContainer registry for Microsoft container images.

Note: This tag has a dependency on the AzureFrontDoor.FirstParty tag.

OutboundYesYesMicrosoftDefenderForEndpointMicrosoft Defender for EndpointBothNoYesPowerBIPower BI.BothNoNoPowerPlatformInfraThis tag represents the IP addresses used by the infrastructure to host Power Platform services.OutboundYesYesPowerPlatformPlexThis tag represents the IP addresses used by the infrastructure to host Power Platform extension execution on behalf of the customer.InboundYesYesPowerQueryOnlinePower Query Online.BothNoNoServiceBusAzure Service Bus traffic that uses the Premium service tier.OutboundYesYesServiceFabricAzure Service Fabric.

Note: This tag represents the Service Fabric service endpoint for control plane per region. This enables customers to perform management operations for their Service Fabric clusters from their VNET endpoint. (For example, https:// westus.servicefabric.azure.com).

BothNoNoSqlAzure SQL Database, Azure Database for MySQL, Azure Database for PostgreSQL, Azure Database for MariaDB, and Azure Synapse Analytics.

Note: This tag represents the service, but not specific instances of the service. For example, the tag represents the Azure SQL Database service, but not a specific SQL database or server. This tag doesn't apply to SQL managed instance.

OutboundYesYesSqlManagementManagement traffic for SQL-dedicated deployments.BothNoYesStorageAzure Storage.

Note: This tag represents the service, but not specific instances of the service. For example, the tag represents the Azure Storage service, but not a specific Azure Storage account.

(Video) What is service tag and how to use it for NSG | Azure Training in Hindi

OutboundYesYesStorageSyncServiceStorage Sync Service.BothNoNoWindowsAdminCenterAllow the Windows Admin Center backend service to communicate with customers' installation of Windows Admin Center.OutboundNoYesWindowsVirtualDesktopAzure Virtual Desktop (formerly Windows Virtual Desktop).BothNoYesVirtualNetworkThe virtual network address space (all IP address ranges defined for the virtual network), all connected on-premises address spaces, peered virtual networks, virtual networks connected to a virtual network gateway, the virtual IP address of the host, and address prefixes used on user-defined routes. This tag might also contain default routes.BothNoNo

Videos

1. How to become Azure Integration Developer | Azure Integration Services Introduction
(Sri Gunnala - Tech Talks)
2. AZ-900 Episode 30 | Azure Resource Tags
(Adam Marczak - Azure for Everyone)
3. Cloud Shell Quick Tip: Service Tag Network Security Group Rule.
(IT Ops Talk)
4. Azure DevOps Service Tags - Secure Your Networking for Azure DevOps
(CoderDave)
5. 5 Tricks to Using Azure Tags Effectively
(KnowOps)
6. Azure Networking | How to use Application Security Group & Service TAG | Network Security Group |V-4
(ITProGuide)
Top Articles
Latest Posts
Article information

Author: Francesca Jacobs Ret

Last Updated: 29/05/2023

Views: 6184

Rating: 4.8 / 5 (68 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Francesca Jacobs Ret

Birthday: 1996-12-09

Address: Apt. 141 1406 Mitch Summit, New Teganshire, UT 82655-0699

Phone: +2296092334654

Job: Technology Architect

Hobby: Snowboarding, Scouting, Foreign language learning, Dowsing, Baton twirling, Sculpting, Cabaret

Introduction: My name is Francesca Jacobs Ret, I am a innocent, super, beautiful, charming, lucky, gentle, clever person who loves writing and wants to share my knowledge and understanding with you.