Technical Tip: How to allow all users to access Azure while blocking all other internet traffic
| Description | This article describes how to configure FortiGate to allow all users to access Microsoft Azure services while restricting access to all other internet traffic. |
| Scope | FortiGate. |
| Solution | The configuration consists of three key firewall policies:
Without a proper DNS resolution mechanism, users won’t be able to reach Azure services by hostname.
After applying the above configuration, users will only be able to access Microsoft Azure services while all other internet traffic remains blocked.
Note: Make sure the Allow policy is above the Block policy. |


