Forum Discussion
Azure Networking: Request for Granular Control of “Allow Azure Services and Resources”
There isn’t a universal Azure-wide mechanism that lets you select any arbitrary resource or managed identity as a trusted-network bypass. The capability depends on the target service. For Azure SQL specifically, the “Allow Azure services and resources” option is intentionally broad and Microsoft recommends using more restrictive network controls where possible. A better least-privilege design would normally be Private Endpoint, or VNet/service-endpoint rules where appropriate, combined with Microsoft Entra authentication/managed identity for authorization. The network rule only determines whether the connection reaches SQL; it doesn’t grant database permissions. I agree that a resource-instance-level trusted-services mechanism would be useful, but today it isn’t implemented consistently across Azure services