Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
Hi Ed Haynes,
- These are not part of the essential service closing points of IP Azure (eg Azure Monitor, Key Vault, or Storage)
- Blocking it does not affect your own azure functionality until you are to communicate with that specific customer (which is not possible)
- They said, because Azure IP is shared, the same IP can be recycled for another customer in the future - so blocking by IP leads to some risk of collateral effect over time.
- Block aggressive IP (s) using Firewall or Web App Firewall (WAF) is safe if you believe that IPS engage in malicious/reconnaissance behavior.
- If Azure (WAF) is used, consider a custom rule for path scanning efforts (eg, blocking the requests targeting wp-clogin.php, xmlrpc.php, etc.).
- Keep a list of scanning IP to seek criminals again and again.
- If you have space, automated detection + blocking using defender for cloud or watchdog.
- If you want, you can report abuse from Azure-host IPS
https://www.microsoft.com/en-us/wdsi/support/report-unsafe-site-guest