How Do You Block Azure IMDS Access with NSG1?

Implement and manage network security groups
Answer Correct answer: D — Add an outbound NSG rule to NSG1 that denies traffic to the AzurePlatformIMDS service tag, blocking VM1's IMDS REST API requests.

You have an Azure subscription that contains a virtual machine named VM1 and a network security group (NSG) named NSG1. NSG1 has the default rules configured. VM1 runs Windows Server 2022 and contains a single NIC named NIC1. NIC1 is associated with NSG1. You need to prevent access to the Azure Instance Metadata Service (IMDS) REST API on VM1. The solution must minimize administrative effort. What should you add to NSG1?

  1. an outbound rule that blocks traffic to an IP address.
  2. an inbound rule that blocks traffic to an IP address.
  3. an inbound and outbound rule that blocks traffic to an application security group.
  4. an outbound rule that blocks traffic to a service tag. Correct Answer

Community Votes

D
71%
A
29%

71% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The tested point is that IMDS is a platform endpoint represented by the AzurePlatformIMDS service tag in NSG rules; the trap is selecting a raw 169.254.169.254 IP rule or an inbound rule instead.

This AZ-700 question asks how to prevent a Windows Server 2022 VM named VM1 from reaching the Azure Instance Metadata Service (IMDS) REST API by adding a rule to NSG1. The answer is an outbound NSG rule that denies traffic to the AzurePlatformIMDS service tag, giving the smallest administrative footprint.

The most common wrong answer is A, an outbound rule blocking a raw IP address, because candidates know IMDS as 169.254.169.254 but overlook that AzurePlatformIMDS is the purpose-built service tag.

Community Discussion (4 comments)

tc0369 👍 2 Selected: A
I would go with A Service tag is used for group of IPs for the same service, eg, Azure Storage, etc. Traffic to IMDS wont leave VM, and with the fix ip as 169.254.169.254.
manhattan 👍 1 Selected: D
it should be D but not 100% sure you can block traffic with outbound rule - service tag to this service "azureplatformIMDS" but this article shows a specific IP that IMDS service runs queries IMDS is a REST API that's available at a well-known, non-routable IP address (169.254.169.254) https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=windows so theoretically you can block the IP too
NK203 👍 2 Selected: D
Default rule already block all the inbound traffic.
maciek8131 👍 2 Selected: D
Correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An outbound NSG rule that blocks traffic to the AzurePlatformIMDS service tag (D) is the supported way to prevent VM1 from reaching the Instance Metadata Service REST API. IMDS listens on the non-routable 169.254.169.254 address, and Azure represents this platform endpoint with the AzurePlatformIMDS service tag so NSG rules can target it without hard-coding the address. Because the VM initiates IMDS queries outbound, a Deny rule in the outbound direction stops the requests before they reach the platform endpoint. Using the service tag also minimizes administrative effort: if Azure changes platform addressing, the tag remains valid. This matches the scenario's requirement to add a single rule to NSG1 and keep ongoing management low.

Why the Other Options Are Wrong

Option A is tempting because IMDS is commonly identified by 169.254.169.254, but a raw destination IP rule is less maintainable and not the purpose-built control for this platform endpoint. Option B places the rule in the inbound direction, yet the default inbound NSG rules already deny unsolicited traffic and the VM's IMDS request is outbound, so an inbound deny does not stop the query from being sent. Option C uses an application security group and requires both inbound and outbound rules, but ASGs group NICs for east-west traffic, not the IMDS platform endpoint, and this approach does not target IMDS at all. None of these alternatives satisfies the "minimize administrative effort" requirement as cleanly as the AzurePlatformIMDS service tag.

Community Comment Notes

tc0369 argued for option A and reasoned that "Traffic to IMDS wont leave VM, and with the fix ip as 169.254.169.254"; that shows the common IP-based instinct, but Azure still exposes AzurePlatformIMDS as the intended NSG destination. manhattan leaned toward D but was "not 100% sure you can block traffic with outbound rule" using the "azureplatformIMDS" tag; the outbound direction is correct because the guest OS originates the IMDS call. NK203 pointed out that the default rules already block all inbound traffic, which reinforces why an inbound-only answer such as B is not the right fix. The community vote strongly favors D, and the service-tag approach aligns with that consensus while explaining why the raw-IP option remains a trap.

Official Reference

Exam Strategy

When an AZ-700 question asks how to control a platform endpoint, look for the dedicated service tag such as AzurePlatformIMDS and confirm the correct traffic direction. Outbound rules filter requests initiated by the VM, while default inbound rules already deny unsolicited inbound, so avoid inbound-only answers.

Frequently Asked Questions

Why not block 169.254.169.254 with an outbound IP rule instead of the AzurePlatformIMDS service tag?

A raw IP rule can be error-prone and harder to maintain; AzurePlatformIMDS is the supported service tag that represents the IMDS endpoint and requires less administrative effort.

Why is an inbound NSG rule not enough to block Azure IMDS on VM1?

IMDS requests are initiated outbound from the VM to 169.254.169.254. An inbound rule does not stop that request, and default inbound rules already deny unsolicited inbound traffic.

Related Analysis

Practice All AZ-700 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-700 Practice Test →

← Back to AZ-700 Study Guide