Hi Sharyn,
If you navigate to an App Service in the portal, click Networking blade, select Enabled from select virtual networks and IP addresses, you can then create Allow/Deny rules to control access to the app.
For example, if you wanted one of internal apps to only be available from your office's public IP address you could use the above technique to accomplish that. You would select Deny for unmatched rule action and then add Allow rule for your office's public IP.
I'm unsure if the above covers what you want to achieve. Please add a comment below with clarification on your goals and if needed I will give further instructions.
Thanks.
-TP