Network Isolation Overview Azure Services that exposes public internet facing endpoints should get compliant with DIAMOND M2 requirements to lock down the endpoint to authorized callers. There are different mechanisms to provide the required network isolation based on the service type. This document covers the different service types and corresponding actions to be taken by each type. You can also review Network Isolation M2 Scope for Network Isolation In scope: All Azure Services with one or more endpoints that are publicly exposed in the Internet (public IP address) are in scope for Network Isolation. Out of Scope: All Azure services with no Public Endpoints are out of scope. (3 sheets of description)