You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell/CLI/ARM自动化实现WebApp的VNet访问限制

Got it, since you already know how to set up VNet access restrictions via the Azure Portal, let's break down how to automate this using PowerShell, Azure CLI, and ARM templates. Each method fits different workflow needs, so pick what works best for you:

Using Azure PowerShell

First, make sure you have the latest Azure PowerShell module installed. Here's a step-by-step command set to add a VNet access restriction rule to your Web App:

# Define your core resource details
$resourceGroupName = "your-resource-group-name"
$webAppName = "your-webapp-name"
$vnetResourceId = "/subscriptions/your-subscription-id/resourceGroups/vnet-rg/providers/Microsoft.Network/virtualNetworks/your-vnet-name"
$subnetId = "$vnetResourceId/subnets/your-subnet-name"

# Add the VNet access restriction rule
Add-AzWebAppAccessRestrictionRule `
    -ResourceGroupName $resourceGroupName `
    -WebAppName $webAppName `
    -Name "Allow VNet Subnet Access" `
    -Priority 100 `
    -Action Allow `
    -VirtualNetworkResourceId $vnetResourceId `
    -SubnetId $subnetId

Quick Notes:

  • The -Priority value needs to be unique—use a lower number than any existing deny rules (if you have them) to ensure this allow rule takes precedence.
  • To lock down access completely, add a deny rule with a higher priority (e.g., 200) targeting 0.0.0.0/0 after setting up your VNet allow rule.
Using Azure CLI

Start by logging into Azure CLI (az login) and setting your target subscription (az account set --subscription your-subscription-id). Then run this command to add the VNet restriction:

az webapp config access-restriction add \
    --resource-group your-resource-group-name \
    --name your-webapp-name \
    --rule-name "Allow VNet Subnet" \
    --priority 100 \
    --action Allow \
    --vnet-name your-vnet-name \
    --subnet your-subnet-name \
    --vnet-resource-group vnet-resource-group-name # Optional, only needed if your VNet is in a different resource group

Pro Tip: To confirm the rule was applied correctly, run:

az webapp config access-restriction list --resource-group your-resource-group-name --name your-webapp-name
Using ARM Template

You can embed the access restriction rule directly into your ARM template under the siteConfig property of the Web App resource. Here's a reusable snippet:

{
  "type": "Microsoft.Web/sites",
  "apiVersion": "2023-01-01",
  "name": "[parameters('webAppName')]",
  "location": "[parameters('location')]",
  "dependsOn": [
    "[resourceId('Microsoft.Web/serverfarms', parameters('appServicePlanName'))]"
  ],
  "properties": {
    "serverFarmId": "[resourceId('Microsoft.Web/serverfarms', parameters('appServicePlanName'))]",
    "siteConfig": {
      "ipSecurityRestrictions": [
        {
          "name": "Allow VNet Subnet Access",
          "priority": 100,
          "action": "Allow",
          "type": "VirtualNetwork",
          "properties": {
            "virtualNetworkSubnetId": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('vnetName'), parameters('subnetName'))]"
          }
        },
        // Optional: Add a default deny rule to block all unapproved traffic
        {
          "name": "Deny All Other Traffic",
          "priority": 200,
          "action": "Deny",
          "type": "IPAddress",
          "properties": {
            "ipAddress": "0.0.0.0/0"
          }
        }
      ]
    }
  }
}

Important Reminders:

  • Replace all placeholder parameters (like parameters('webAppName')) with your actual values, or define them in the template's parameters section.
  • Ensure your Web App has VNet integration enabled if you're using a VNet without service endpoints (service endpoints are the recommended approach for this scenario).

内容的提问来源于stack exchange,提问作者ChethanR

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:27:48