Hello Sean Kelly,
Thanks for your question
There can be many reasons. While you've created an inbound rule on the VNET, the VM itself might have its own firewall blocking access on port 1433.
You can also use nslookup to see if the container is resolving the hostname.
You can mark it 'Accept Answer' and 'Upvote' if this helped you
Regards,
Abiola