Details about Azure Application Security Group and how they work you can find here:
https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups
I read the limitation "Application security groups that can be specified within all security rules of a network security group" this way:
- In a NSG you can have up to 1000 NSG rules
- In max 100 of this 1000 NSG rules you can specify an Application Security Group as a source or destination
The advantage of Application Security group is reducing the complexity and maintenance of NSG rules for specific groups of VMs and IPs.
----------
(If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)
Regards
Andreas Baumgarten