A global e-commerce company uses Azure App Service to host its regional web applications. Each application needs to access a separate Azure SQL Database instance. To minimize the attack surface and ensure that applications can only connect to their designated database, the security team wants to prevent the App Services from initiating connections to any other Azure SQL Database instances or public endpoints. The solution must utilize Managed Identities for authentication. Which security configuration should be applied to the App Services?
- AApply IP Restrictions on the App Service to allow outbound traffic only to specific SQL Database public IP addresses and use Managed Identities.
- BConfigure VNet Integration (Regional) with Network Security Groups (NSGs) on the integrated subnet and use Managed Identities.
- CDeploy App Service Environments (ASEv3) for each region, place App Services in them, and use Managed Identities.
- DImplement Azure Private Endpoint for each Azure SQL Database and configure Private DNS zones for resolution, then use Managed Identities.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure VNet Integration (Regional) with Network Security Groups (NSGs) on the integrated subnet and use Managed Identities.
Configuring VNet Integration (Regional) for the App Service allows its outbound traffic to flow through a designated subnet within your virtual network. By applying Network Security Groups (NSGs) to this integrated subnet, you can precisely control the outbound traffic from the App Service, allowing connections only to the specific Azure SQL Database instances and blocking all other outbound traffic, including to other SQL databases or public endpoints. Managed Identities can then be used for secure, password-less authentication to the allowed SQL Databases.
Why the other options are wrong
- A. IP Restrictions on App Service primarily control *inbound* traffic. For outbound control, while you can configure outbound restrictions, NSGs on a VNet-integrated subnet provide more robust and dynamic control over destination endpoints than static IP lists.
- C. ASEv3 provides complete network isolation, which would achieve the goal, but it's a dedicated, higher-cost solution for full VNet deployment. VNet Integration with NSGs is a more granular and cost-effective approach for controlling *outbound* access from a standard App Service plan, which is what the question implies by focusing on blocking connections to *other* databases.
- D. While Private Endpoints secure inbound access to SQL DBs and provide private connectivity, they don't inherently restrict the *outbound* connections from the App Service to other databases or public endpoints. The App Service would still have a public outbound path unless VNet Integrated.
App Service VNet Integration (Regional) with NSGs for Outbound Control
A networking feature that routes outbound traffic from an Azure App Service through a subnet in a virtual network, enabling granular control over destination endpoints using Network Security Groups (NSGs).
- Enables outbound traffic filtering for App Service.
- Uses a delegated subnet within a VNet.
- NSGs on the subnet define allowed outbound destinations (IPs, FQDNs, Service Tags).
Memory trick: VNet Integration + NSG = Your App Service's outbound traffic police.