It is not recommended that you allow any address on the internet to access any port in your structure, there are automatic scans that will quickly identify the listening ports in your structure and you may suffer attacks.
nsg is already a great constraint, but I don't recommend keeping any any-any rules
There are some best practices articles for the solutions, below are some:
reference: https://learn.microsoft.com/en-us/azure/architecture/framework/services/networking/azure-firewall
Get in touch if you need more help with this issue.
--please don't forget to "[Accept the answer]" if the reply is helpful--