Apologies for the delayed response here.
Depending on how your PaaS services are integrated within the VNET. Like for example based on this architecture where Azure App service and Azure SQL are integrated in a VNET using Private Endpoints you can secure both ingress and egress traffic using an Azure Firewall.
Please let me know if you have any additional questions here.