# Keep managed Service Fabric NSG overrides inside the supported priority band

> Which automatically created Service Fabric network rules can a custom NSG rule override?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-220-keep-managed-service-fabric-nsg-overrides-inside-the-supported-priority-band/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:16+00:00
- Modified: 2026-09-10T01:20:46+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which automatically created Service Fabric network rules can a custom NSG rule override?

## Potentially affected

Azure Service Fabric managed clusters with custom network security rules.

## DSE recommendation

DSE recommends classifying a proposed exception as an override of an optional rule or a conflict with required provider access.

## Article

## Source facts

Service Fabric managed clusters reserve NSG priorities 0–999 for essential functionality and prohibit custom rules below 1000. Custom rules belong in priorities 1000–3000 and can override the optional rules placed at 3001–4000. The provider-access rule for the cluster client and HTTP gateway ports is always created and cannot be overridden. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/service-fabric/how-to-managed-cluster-networking).

## Applicability

Use this distinction when reviewing the managed cluster’s networkSecurityRules configuration. Identify the actual rule being challenged before selecting a priority. This article addresses the managed service’s rule-ownership boundary, not a general Windows Firewall precedence policy or permission to open an application port.

## DSE recommendation

DSE recommends classifying a proposed exception as an override of an optional rule or a conflict with required provider access. Record the target rule, traffic direction, ports and intended scope. If the design assumes that a custom deny can suppress the provider’s mandatory gateway rule, return that assumption to the architecture owner instead of trying increasingly aggressive priority values. Keep application access requests separate from service-management requirements.

## Verification

Review the deployed effective rules against the proposed configuration in a controlled cluster. Confirm that the custom rule falls within the supported band and affects only the optional traffic being changed. Check both the intended allowed or denied application path and continued management access. Preserve the observed rule identifiers and priorities with the change record; the presence of a custom rule alone does not show which traffic it controls.

## Official references

[Microsoft Learn](https://learn.microsoft.com/en-us/azure/service-fabric/how-to-managed-cluster-networking). Source retrieved September 9, 2026.

## Primary reference

- Name: Configure network settings for Service Fabric managed clusters - Azure Service Fabric | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/service-fabric/how-to-managed-cluster-networking
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep managed Service Fabric NSG overrides inside the supported priority band,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-220-keep-managed-service-fabric-nsg-overrides-inside-the-supported-priority-band/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
