Network Security Perimeter (NSP) allows organizations to define a logical network isolation boundary for PaaS resources (for example, Azure Storage accounts and SQL Database servers) that are deployed outside your organization's virtual networks. It restricts public network access to PaaS resources within the perimeter; access can be exempted using explicit access rules for public inbound and outbound traffic.

Network Security Perimeter overview

Official Microsoft documentation: Network security perimeter concepts

Pain points

Existing patterns

Here are the existing patterns to avoid public endpoints and secure access:

Network access control features in Azure

Azure Network Security Perimeter for PaaS resources

Overview

Deployment

The main steps are: deploy the perimeter from the Azure portal, create inbound and outbound access rules, associate resources to the perimeter, and adjust the associated resources' access modes as needed.