# Inspect every evaluated security-rule layer before opening Bastion access

> Use NSG diagnostics to locate the rule that denies the tested connection rather than stopping at a subnet allow rule.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-218-inspect-every-evaluated-security-rule-layer-before-opening-bastion-access/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:18+00:00
- Modified: 2026-09-10T01:20:46+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Use NSG diagnostics to locate the rule that denies the tested connection rather than stopping at a subnet allow rule.

## Potentially affected

Azure VM connections evaluated by Network Watcher NSG diagnostics across network security groups and Virtual Network Manager rules.

## DSE recommendation

Capture the evaluated layers and exact denying rule before proposing a narrowly scoped access change.

## Article

## Source facts

Network Watcher NSG diagnostics evaluates whether traffic is permitted by the applied security rules, including network security groups and Virtual Network Manager. Microsoft’s Bastion example illustrates a connection allowed at the network-admin and subnet layers but denied by the VM’s NIC-level group.

For that example, Microsoft’s correction is an appropriately higher-priority allow rule, or an edit to the denying rule. A smaller priority number represents higher priority in the documented NSG rule change. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/network-watcher/diagnose-network-security-rules).

## Applicability

Define the actual source, destination, protocol, port and direction for the failed connection. Treat the tutorial addresses and permissive test selections as examples, not a ready-made production access policy.

## DSE recommendation

DSE recommends preserving the diagnostics result and identifying the rule owner before making a change. Review every evaluated layer and tie the proposed exception to the intended management source and service. Avoid adding broad allowances merely because the first visible subnet rule appears correct; document which specific denial the proposal addresses.

## Verification

Rerun diagnostics for the same connection profile after an approved change and compare the matched rules. Test the intended Bastion connection itself, then check a representative source or port that should remain denied. Keep both the allowed and denied results with the final rule scope. Continue investigating other connection problems if rule evaluation permits the traffic but the session still fails.

## Official references

[Microsoft Learn: Check Security Rules Using NSG Diagnostics](https://learn.microsoft.com/en-us/azure/network-watcher/diagnose-network-security-rules). Source retrieved September 9, 2026.

## Primary reference

- Name: Check Security Rules Using NSG Diagnostics - Azure Network Watcher | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/network-watcher/diagnose-network-security-rules
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Inspect every evaluated security-rule layer before opening Bastion access,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-218-inspect-every-evaluated-security-rule-layer-before-opening-bastion-access/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
