@Alan Hammond Thank you for reaching out to Microsoft Q&A.
I understand that the PCI Compliance scanner cannot reach the VM even though there is an Allow ANY rule to the VM on port 443. Can you add another rule allowing this PCI scanner IP with lowest priority and see if that helps?
Please also check the effective security group rules to check the rules that are actually being applied to determine that nothing is blocking this traffic. Hope this helps.