How Do You Block Azure IMDS Access with NSG1?
You have an Azure subscription that contains a virtual machine named VM1 and a network security group (NSG) named NSG1. NSG1 has the default rules configured. VM1 runs Windows Server 2022 and contains a single NIC named NIC1. NIC1 is associated with NSG1. You need to prevent access to the Azure Instance Metadata Service (IMDS) REST API on VM1. The solution must minimize administrative effort. What should you add to NSG1?
Community Votes
71% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The tested point is that IMDS is a platform endpoint represented by the AzurePlatformIMDS service tag in NSG rules; the trap is selecting a raw 169.254.169.254 IP rule or an inbound rule instead.
This AZ-700 question asks how to prevent a Windows Server 2022 VM named VM1 from reaching the Azure Instance Metadata Service (IMDS) REST API by adding a rule to NSG1. The answer is an outbound NSG rule that denies traffic to the AzurePlatformIMDS service tag, giving the smallest administrative footprint.
The most common wrong answer is A, an outbound rule blocking a raw IP address, because candidates know IMDS as 169.254.169.254 but overlook that AzurePlatformIMDS is the purpose-built service tag.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An outbound NSG rule that blocks traffic to the AzurePlatformIMDS service tag (D) is the supported way to prevent VM1 from reaching the Instance Metadata Service REST API. IMDS listens on the non-routable 169.254.169.254 address, and Azure represents this platform endpoint with the AzurePlatformIMDS service tag so NSG rules can target it without hard-coding the address. Because the VM initiates IMDS queries outbound, a Deny rule in the outbound direction stops the requests before they reach the platform endpoint. Using the service tag also minimizes administrative effort: if Azure changes platform addressing, the tag remains valid. This matches the scenario's requirement to add a single rule to NSG1 and keep ongoing management low.Why the Other Options Are Wrong
Option A is tempting because IMDS is commonly identified by 169.254.169.254, but a raw destination IP rule is less maintainable and not the purpose-built control for this platform endpoint. Option B places the rule in the inbound direction, yet the default inbound NSG rules already deny unsolicited traffic and the VM's IMDS request is outbound, so an inbound deny does not stop the query from being sent. Option C uses an application security group and requires both inbound and outbound rules, but ASGs group NICs for east-west traffic, not the IMDS platform endpoint, and this approach does not target IMDS at all. None of these alternatives satisfies the "minimize administrative effort" requirement as cleanly as the AzurePlatformIMDS service tag.Community Comment Notes
tc0369 argued for option A and reasoned that "Traffic to IMDS wont leave VM, and with the fix ip as 169.254.169.254"; that shows the common IP-based instinct, but Azure still exposes AzurePlatformIMDS as the intended NSG destination. manhattan leaned toward D but was "not 100% sure you can block traffic with outbound rule" using the "azureplatformIMDS" tag; the outbound direction is correct because the guest OS originates the IMDS call. NK203 pointed out that the default rules already block all inbound traffic, which reinforces why an inbound-only answer such as B is not the right fix. The community vote strongly favors D, and the service-tag approach aligns with that consensus while explaining why the raw-IP option remains a trap.Official Reference
Exam Strategy
When an AZ-700 question asks how to control a platform endpoint, look for the dedicated service tag such as AzurePlatformIMDS and confirm the correct traffic direction. Outbound rules filter requests initiated by the VM, while default inbound rules already deny unsolicited inbound, so avoid inbound-only answers.
Frequently Asked Questions
Why not block 169.254.169.254 with an outbound IP rule instead of the AzurePlatformIMDS service tag?
A raw IP rule can be error-prone and harder to maintain; AzurePlatformIMDS is the supported service tag that represents the IMDS endpoint and requires less administrative effort.
Why is an inbound NSG rule not enough to block Azure IMDS on VM1?
IMDS requests are initiated outbound from the VM to 169.254.169.254. An inbound rule does not stop that request, and default inbound rules already deny unsolicited inbound traffic.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →