There is no additional costs for using Azure default outbound access.
You may consider improving security by using Network Security Groups (NSGs), Azure Firewall, private endpoints, secure VNets, and continuous monitoring with Azure Monitor and Azure Security Center.
Further Enhancements:
Limit Access by IP:
- Using an Azure NAT Gateway, you can provide a fixed IP address for outbound traffic from your VMSS instances.
- Configure your AWS S3 bucket policy to allow access only from this IP address to enhance security.
Review the Azure DevOps Security Best Practices, for securing your network.