What you need to know
Enhanced network controls remove certain management allowances, not the need for health probes, authorized clients or backend connectivity.
Potentially affected
Application Gateway v2 private deployments registered for enhanced network controls.
DSE recommendation
Review health-probe, client and backend paths separately before applying restrictive subnet rules.
Source facts
For registered private Application Gateway v2 deployments, Microsoft removes the requirement for inbound GatewayManager and outbound Internet allowances. Inbound AzureLoadBalancer traffic is still required for health probes.
The documentation’s restrictive NSG example separately permits client traffic and outbound backend traffic. Microsoft warns that deny-all rules can block intended clients or backends; blocking the backend path can cause failed health and 5XX responses. Private deployments also require subnet delegation to Microsoft.Network/applicationGateways. Microsoft Learn.
Applicability
Confirm feature registration, deployment context and subnet delegation. A pre-feature gateway sharing the subnet prevents use of the enhanced controls until earlier gateways are reprovisioned or new gateways use another subnet. Include coexisting gateways in the review, not just the one being edited.
DSE recommendation
DSE recommends a three-part rule review: platform probes, approved client-to-listener access and gateway-to-backend access. Identify each required path from the actual design before adding deny-all rules. Keep documented example addresses out of production configuration. Have the application and network owners agree which tests will distinguish a rejected client from an unreachable backend.
Verification
In an approved test, inspect probe health and exercise both permitted and excluded client requests. Verify the intended backend is reached and that its health remains acceptable after the NSG change. Preserve the effective rules and observations together. If 5XX responses appear, investigate the backend path as well as the listener before declaring the private gateway itself unavailable.
Official references
Microsoft Learn: Private Application Gateway deployment. Source retrieved September 9, 2026.
Review the official source
Private Application Gateway deployment - Azure Application Gateway | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE