Hi @諏訪 大空
If I understand the question, you want to update the vm without having to connect via NSG, right?
In addition to being able to use JIT,and Bastion,
You can use Azure Update Manager o apply security updates,
Create a maintenance configuration:
On Updates tab, selecte Security and Critical Updates:
Get in touch if you need more help with this issue. --please don't forget to "[Accept the answer]" if the reply is helpful--