Inspect every evaluated security-rule layer before opening Bastion access

Use NSG diagnostics to locate the rule that denies the tested connection rather than stopping at a subnet allow rule.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Use NSG diagnostics to locate the rule that denies the tested connection rather than stopping at a subnet allow rule.

Potentially affected

Azure VM connections evaluated by Network Watcher NSG diagnostics across network security groups and Virtual Network Manager rules.

DSE recommendation

Capture the evaluated layers and exact denying rule before proposing a narrowly scoped access change.

Source facts

Network Watcher NSG diagnostics evaluates whether traffic is permitted by the applied security rules, including network security groups and Virtual Network Manager. Microsoft’s Bastion example illustrates a connection allowed at the network-admin and subnet layers but denied by the VM’s NIC-level group.

For that example, Microsoft’s correction is an appropriately higher-priority allow rule, or an edit to the denying rule. A smaller priority number represents higher priority in the documented NSG rule change. Microsoft Learn.

Applicability

Define the actual source, destination, protocol, port and direction for the failed connection. Treat the tutorial addresses and permissive test selections as examples, not a ready-made production access policy.

DSE recommendation

DSE recommends preserving the diagnostics result and identifying the rule owner before making a change. Review every evaluated layer and tie the proposed exception to the intended management source and service. Avoid adding broad allowances merely because the first visible subnet rule appears correct; document which specific denial the proposal addresses.

Verification

Rerun diagnostics for the same connection profile after an approved change and compare the matched rules. Test the intended Bastion connection itself, then check a representative source or port that should remain denied. Keep both the allowed and denied results with the final rule scope. Continue investigating other connection problems if rule evaluation permits the traffic but the session still fails.

Official references

Microsoft Learn: Check Security Rules Using NSG Diagnostics. Source retrieved September 9, 2026.

Primary reference

Review the official source

Check Security Rules Using NSG Diagnostics - Azure Network Watcher | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE