Use NSG logs in combination with Traffic Analytics to identify legitimate outbound connectivity
https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin