NSG pushed to subnets breaks the lab

Jun Ye 0 Reputation points
2025-03-04T21:49:52.7433333+00:00

In this lab: https://learn.microsoft.com/en-us/training/modules/secure-and-isolate-with-nsg-and-service-endpoints/3-exercise-network-security-groups

Right after the vNets and subnets were created, there appears to be a policy enforcement linked a NSG to the subnets. I cannot remove the NSG nor can I change the NSG to the intended NSG that's supposed to be in the lab.

Had to use my own subscription.

Azure | Azure Training
{count} votes

1 answer

Sort by: Most helpful
  1. Rakesh Gurram 15,715 Reputation points Microsoft External Staff Moderator
    2025-03-25T08:29:00.1866667+00:00

    Hi Jun Ye,

    We contacted the content author and received confirmation that the default NSG created by policy can be ignored, as it does not affect the lab's functionality. In this lab, the NSG assigned to the NICs of the VMs takes precedence over any NSG assigned to the VNet or subnet.

    Additionally, please be aware that SSH connections may temporarily fail after the NSG rules are applied. If this happens, waiting a minute or so should resolve the issue and allow the connection to work as expected.

    Please Accept the Answer so that it will be useful for others in the community.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.