What you need to know
Use NSG diagnostics to locate the rule that denies the tested connection rather than stopping at a subnet allow rule.
Potentially affected
Azure VM connections evaluated by Network Watcher NSG diagnostics across network security groups and Virtual Network Manager rules.
DSE recommendation
Capture the evaluated layers and exact denying rule before proposing a narrowly scoped access change.
Source facts
Network Watcher NSG diagnostics evaluates whether traffic is permitted by the applied security rules, including network security groups and Virtual Network Manager. Microsoft’s Bastion example illustrates a connection allowed at the network-admin and subnet layers but denied by the VM’s NIC-level group.
For that example, Microsoft’s correction is an appropriately higher-priority allow rule, or an edit to the denying rule. A smaller priority number represents higher priority in the documented NSG rule change. Microsoft Learn.
Applicability
Define the actual source, destination, protocol, port and direction for the failed connection. Treat the tutorial addresses and permissive test selections as examples, not a ready-made production access policy.
DSE recommendation
DSE recommends preserving the diagnostics result and identifying the rule owner before making a change. Review every evaluated layer and tie the proposed exception to the intended management source and service. Avoid adding broad allowances merely because the first visible subnet rule appears correct; document which specific denial the proposal addresses.
Verification
Rerun diagnostics for the same connection profile after an approved change and compare the matched rules. Test the intended Bastion connection itself, then check a representative source or port that should remain denied. Keep both the allowed and denied results with the final rule scope. Continue investigating other connection problems if rule evaluation permits the traffic but the session still fails.
Official references
Microsoft Learn: Check Security Rules Using NSG Diagnostics. Source retrieved September 9, 2026.
Review the official source
Check Security Rules Using NSG Diagnostics - Azure Network Watcher | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE