Hi,
Thank you for posting the question to the Q&A forum.
Unlike Azure Firewall, which monitors all traffic for workloads, NSG is commonly deployed for individual vNets, subnets, and network interfaces for virtual machines to refine traffic. It does so by activating a rule (allow or deny) or Access Control List (ACL), which allows or denies traffic to Azure resources.
You can find more about NSG here : [https://learn.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview
You can find more about Azure Firewall here: [https://learn.microsoft.com/en-us/training/modules/introduction-azure-firewall/
I hope the above information can help you.
If the ANSWER is helpful, please click "Accept Answer" and upvote it. Thanks