Preserve probes and application paths in a private Application Gateway NSG

Enhanced network controls remove certain management allowances, not the need for health probes, authorized clients or backend connectivity.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Enhanced network controls remove certain management allowances, not the need for health probes, authorized clients or backend connectivity.

Potentially affected

Application Gateway v2 private deployments registered for enhanced network controls.

DSE recommendation

Review health-probe, client and backend paths separately before applying restrictive subnet rules.

Source facts

For registered private Application Gateway v2 deployments, Microsoft removes the requirement for inbound GatewayManager and outbound Internet allowances. Inbound AzureLoadBalancer traffic is still required for health probes.

The documentation’s restrictive NSG example separately permits client traffic and outbound backend traffic. Microsoft warns that deny-all rules can block intended clients or backends; blocking the backend path can cause failed health and 5XX responses. Private deployments also require subnet delegation to Microsoft.Network/applicationGateways. Microsoft Learn.

Applicability

Confirm feature registration, deployment context and subnet delegation. A pre-feature gateway sharing the subnet prevents use of the enhanced controls until earlier gateways are reprovisioned or new gateways use another subnet. Include coexisting gateways in the review, not just the one being edited.

DSE recommendation

DSE recommends a three-part rule review: platform probes, approved client-to-listener access and gateway-to-backend access. Identify each required path from the actual design before adding deny-all rules. Keep documented example addresses out of production configuration. Have the application and network owners agree which tests will distinguish a rejected client from an unreachable backend.

Verification

In an approved test, inspect probe health and exercise both permitted and excluded client requests. Verify the intended backend is reached and that its health remains acceptable after the NSG change. Preserve the effective rules and observations together. If 5XX responses appear, investigate the backend path as well as the listener before declaring the private gateway itself unavailable.

Official references

Microsoft Learn: Private Application Gateway deployment. Source retrieved September 9, 2026.

Primary reference

Review the official source

Private Application Gateway deployment - Azure Application Gateway | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE