Summary
In this chapter, you learned how to implement network segmentation for Azure virtual network workloads using NSGs and ASGs. You also learned how the Azure PaaS Firewall can restrict public access to supported PaaS services such as Azure Storage, and how service endpoint features can be used to access supported PaaS services privately over the Azure backbone network.
Finally, we covered how the Azure Bastion service can be used to securely connect to virtual network VMs over the internet without publicly exposing them.
The information in this chapter has equipped you with the skills needed to implement secure access to your Azure virtual network workloads. In the next chapter, you will learn how to implement host security best practices in Azure. See you in the next chapter!