{"id":20896,"date":"2018-01-18T17:22:01","date_gmt":"2018-01-18T17:22:01","guid":{"rendered":"https:\/\/aidanfinn.com\/?p=20896"},"modified":"2018-01-20T09:48:40","modified_gmt":"2018-01-20T09:48:40","slug":"azure-vms-block-outbound-traffic-to-the-internet-updated","status":"publish","type":"post","link":"https:\/\/aidanfinn.com\/?p=20896","title":{"rendered":"Azure VMs&ndash;Block Outbound Traffic to the Internet (Updated)"},"content":{"rendered":"<p>In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that.<\/p>\n<p>Here\u2019s what would happen:<\/p>\n<ul>\n<li>You created an outbound rule to Deny all traffic to a service tag (location) called Internet.<\/li>\n<li>The VM worked fine \u2026 for a while.<\/li>\n<li>The VM was rebooted, maybe for a guest OS patch cycle.<\/li>\n<li>The VM would not reboot.<\/li>\n<li>Your boss screamed at you, if you were lucky.<\/li>\n<\/ul>\n<p>The problem is that Azure included all Azure services under the service tag of \u201cInternet\u201d. And Azure VMs need to talk to Azure to boot up \u2013 to be specific, they need to talk to Azure Storage if the IaaSDiagnostics (Azure Performance Diagnostics) extension is configured. If a VM can\u2019t talk to that storage account, the VM will fail to boot. There was a scripted <a href=\"https:\/\/blogs.technet.microsoft.com\/keithmayer\/2016\/01\/12\/step-by-step-automate-building-outbound-network-security-groups-rules-via-azure-resource-manager-arm-and-powershell\/\" target=\"_blank\" rel=\"noopener\">workaround<\/a>, but it was <em>far<\/em> from pretty.<\/p>\n<p>Recently Microsoft made a <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-network\/security-overview#service-tags\" target=\"_blank\" rel=\"noopener\">Network Security Group service tags<\/a> generally available. Service tags take those old locations and expand them to more than just Virtual Network, Load Balancer (probe), and Internet. Now you can specify Azure storage (storage account) and Azure SQL services, globally and locally (a specific region).<\/p>\n<p align=\"center\"><a href=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/image.png\"><img loading=\"lazy\" decoding=\"async\" style=\"border: 0px currentcolor; display: inline; background-image: none;\" title=\"image\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/image_thumb.png\" alt=\"image\" width=\"270\" height=\"712\" border=\"0\" \/><\/a><\/p>\n<p align=\"left\">So for example, I can let a VM connect (Azure) Storage globally, in West Europe, or to connect to Azure SQL in North Europe. Now we can block outbound access to the Internet, but still allow access to Azure storage in the same region for diagnostics &amp; metrics.<\/p>\n<p align=\"center\"><a href=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/image-1.png\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; border: 0px currentcolor; display: inline; background-image: none;\" title=\"image\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/image_thumb-1.png\" alt=\"image\" width=\"600\" height=\"48\" border=\"0\" \/><\/a><\/p>\n<p align=\"left\">I\u2019ve tested, and yes, my VM rebooted <img decoding=\"async\" class=\"wlEmoticon wlEmoticon-smile\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/wlEmoticon-smile.png\" alt=\"Smile\" \/><\/p>\n<h2>Was This Post Useful?<\/h2>\n<p>If you found this information useful, then imagine what 2 days of training might mean to you. I&#8217;m delivering a 2-day course in Amsterdam on April 19-20, teaching newbies and experienced Azure admins about Azure Infrastructure. There&#8217;ll be lots of in-depth information, covering the foundations, best practices, troubleshooting, and advanced configurations. You can learn more <a href=\"http:\/\/amsterdam.cloudmechanix.com\/\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<p><a href=\"http:\/\/amsterdam.cloudmechanix.com\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-20919\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/AMS-Apr-2018-Cloud-Mechanix.png\" alt=\"\" width=\"600\" height=\"318\" srcset=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/AMS-Apr-2018-Cloud-Mechanix.png 1352w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/AMS-Apr-2018-Cloud-Mechanix-300x159.png 300w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/AMS-Apr-2018-Cloud-Mechanix-768x407.png 768w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2018\/01\/AMS-Apr-2018-Cloud-Mechanix-1024x543.png 1024w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that. Here\u2019s what would happen: You created an outbound rule to Deny all traffic to a service tag (location) called Internet. &hellip; <a href=\"https:\/\/aidanfinn.com\/?p=20896\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Azure VMs&ndash;Block Outbound Traffic to the Internet (Updated)&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":19553,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"_wpcom_ai_launchpad_first_post":false,"footnotes":""},"categories":[5],"tags":[170,242,243,80,190,244],"class_list":["post-20896","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure","tag-azure","tag-firewall","tag-network-security-groups","tag-networking","tag-security","tag-service-tags"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that. Here\u2019s what would happen: You created an outbound rule to Deny all traffic to a service tag (location) called Internet.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"AFinn\"\/>\n\t<meta name=\"google-site-verification\" content=\"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/aidanfinn.com\/?p=20896\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_GB\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\" \/>\n\t\t<meta property=\"og:type\" content=\"activity\" \/>\n\t\t<meta property=\"og:title\" content=\"Azure VMs\u2013Block Outbound Traffic to the Internet (Updated) | Aidan Finn, IT Pro\" \/>\n\t\t<meta property=\"og:description\" content=\"In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that. Here\u2019s what would happen: You created an outbound rule to Deny all traffic to a service tag (location) called Internet.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/aidanfinn.com\/?p=20896\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@joe_elway\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Azure VMs\u2013Block Outbound Traffic to the Internet (Updated) | Aidan Finn, IT Pro\" \/>\n\t\t<meta name=\"twitter:description\" content=\"In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that. Here\u2019s what would happen: You created an outbound rule to Deny all traffic to a service tag (location) called Internet.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@joe_elway\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#article\",\"name\":\"Azure VMs\\u2013Block Outbound Traffic to the Internet (Updated) | Aidan Finn, IT Pro\",\"headline\":\"Azure VMs&ndash;Block Outbound Traffic to the Internet (Updated)\",\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/wp-content\\\/uploads\\\/2016\\\/06\\\/firewall.png\",\"width\":3200,\"height\":1786},\"datePublished\":\"2018-01-18T17:22:01+00:00\",\"dateModified\":\"2018-01-20T09:48:40+00:00\",\"inLanguage\":\"en-GB\",\"commentCount\":1,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#webpage\"},\"articleSection\":\"Azure, Azure, Firewall, Network Security Groups, Networking, Security, Service Tags\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/aidanfinn.com\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"name\":\"Azure\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"position\":2,\"name\":\"Azure\",\"item\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#listItem\",\"name\":\"Azure VMs&ndash;Block Outbound Traffic to the Internet (Updated)\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#listItem\",\"position\":3,\"name\":\"Azure VMs&ndash;Block Outbound Traffic to the Internet (Updated)\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"name\":\"Azure\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#webpage\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896\",\"name\":\"Azure VMs\\u2013Block Outbound Traffic to the Internet (Updated) | Aidan Finn, IT Pro\",\"description\":\"In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that. Here\\u2019s what would happen: You created an outbound rule to Deny all traffic to a service tag (location) called Internet.\",\"inLanguage\":\"en-GB\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/wp-content\\\/uploads\\\/2016\\\/06\\\/firewall.png\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896\\\/#mainImage\",\"width\":3200,\"height\":1786},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=20896#mainImage\"},\"datePublished\":\"2018-01-18T17:22:01+00:00\",\"dateModified\":\"2018-01-20T09:48:40+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/\",\"name\":\"Aidan Finn, IT Pro\",\"description\":\"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\",\"inLanguage\":\"en-GB\",\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Azure VMs\u2013Block Outbound Traffic to the Internet (Updated) | Aidan Finn, IT Pro","description":"In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that. Here\u2019s what would happen: You created an outbound rule to Deny all traffic to a service tag (location) called Internet.","canonical_url":"https:\/\/aidanfinn.com\/?p=20896","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/aidanfinn.com\/?p=20896#article","name":"Azure VMs\u2013Block Outbound Traffic to the Internet (Updated) | Aidan Finn, IT Pro","headline":"Azure VMs&ndash;Block Outbound Traffic to the Internet (Updated)","author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"publisher":{"@id":"https:\/\/aidanfinn.com\/#person"},"image":{"@type":"ImageObject","url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2016\/06\/firewall.png","width":3200,"height":1786},"datePublished":"2018-01-18T17:22:01+00:00","dateModified":"2018-01-20T09:48:40+00:00","inLanguage":"en-GB","commentCount":1,"mainEntityOfPage":{"@id":"https:\/\/aidanfinn.com\/?p=20896#webpage"},"isPartOf":{"@id":"https:\/\/aidanfinn.com\/?p=20896#webpage"},"articleSection":"Azure, Azure, Firewall, Network Security Groups, Networking, Security, Service Tags"},{"@type":"BreadcrumbList","@id":"https:\/\/aidanfinn.com\/?p=20896#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/#listItem","position":1,"name":"Home","item":"https:\/\/aidanfinn.com\/","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","name":"Azure"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","position":2,"name":"Azure","item":"https:\/\/aidanfinn.com\/?cat=5","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=20896#listItem","name":"Azure VMs&ndash;Block Outbound Traffic to the Internet (Updated)"},"previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=20896#listItem","position":3,"name":"Azure VMs&ndash;Block Outbound Traffic to the Internet (Updated)","previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","name":"Azure"}}]},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/#person","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=20896#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/?author=1#author","url":"https:\/\/aidanfinn.com\/?author=1","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=20896#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"WebPage","@id":"https:\/\/aidanfinn.com\/?p=20896#webpage","url":"https:\/\/aidanfinn.com\/?p=20896","name":"Azure VMs\u2013Block Outbound Traffic to the Internet (Updated) | Aidan Finn, IT Pro","description":"In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that. Here\u2019s what would happen: You created an outbound rule to Deny all traffic to a service tag (location) called Internet.","inLanguage":"en-GB","isPartOf":{"@id":"https:\/\/aidanfinn.com\/#website"},"breadcrumb":{"@id":"https:\/\/aidanfinn.com\/?p=20896#breadcrumblist"},"author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"creator":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"image":{"@type":"ImageObject","url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2016\/06\/firewall.png","@id":"https:\/\/aidanfinn.com\/?p=20896\/#mainImage","width":3200,"height":1786},"primaryImageOfPage":{"@id":"https:\/\/aidanfinn.com\/?p=20896#mainImage"},"datePublished":"2018-01-18T17:22:01+00:00","dateModified":"2018-01-20T09:48:40+00:00"},{"@type":"WebSite","@id":"https:\/\/aidanfinn.com\/#website","url":"https:\/\/aidanfinn.com\/","name":"Aidan Finn, IT Pro","description":"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","inLanguage":"en-GB","publisher":{"@id":"https:\/\/aidanfinn.com\/#person"}}]},"og:locale":"en_GB","og:site_name":"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","og:type":"activity","og:title":"Azure VMs\u2013Block Outbound Traffic to the Internet (Updated) | Aidan Finn, IT Pro","og:description":"In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that. Here\u2019s what would happen: You created an outbound rule to Deny all traffic to a service tag (location) called Internet.","og:url":"https:\/\/aidanfinn.com\/?p=20896","twitter:card":"summary","twitter:site":"@joe_elway","twitter:title":"Azure VMs\u2013Block Outbound Traffic to the Internet (Updated) | Aidan Finn, IT Pro","twitter:description":"In theory, it was possible to deny all outbound traffic to the Internet from an Azure VM. In theory, I can also place a loaded gun to my head, but my doctor disapproves of that. Here\u2019s what would happen: You created an outbound rule to Deny all traffic to a service tag (location) called Internet.","twitter:creator":"@joe_elway"},"aioseo_meta_data":{"post_id":"20896","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":"","og_description":"","og_object_type":"activity","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"","og_article_tags":"","twitter_use_og":false,"twitter_card":"summary","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2020-12-21 03:53:23","updated":"2025-06-04 17:18:51","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\/?cat=5\" title=\"Azure\">Azure<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAzure VMs\u2013Block Outbound Traffic to the Internet (Updated)\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/aidanfinn.com\/"},{"label":"Azure","link":"https:\/\/aidanfinn.com\/?cat=5"},{"label":"Azure VMs&ndash;Block Outbound Traffic to the Internet (Updated)","link":"https:\/\/aidanfinn.com\/?p=20896"}],"amp_enabled":true,"jetpack_featured_media_url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2016\/06\/firewall.png","_links":{"self":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/20896","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20896"}],"version-history":[{"count":3,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/20896\/revisions"}],"predecessor-version":[{"id":20923,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/20896\/revisions\/20923"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/media\/19553"}],"wp:attachment":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20896"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20896"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20896"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}