 Hey, it's Jay Gordon. I'm a cloud advocate with Microsoft and if you've got less than three minutes Then you're going to be able to learn how to configure a virtual network service tag So that we can SSH into a virtual machine and not have to worry about Configuring any IP based networking rules in our network security group. So let's jump into what an NSG is What a network service tag rule is and then eventually we'll create one a Network security group kind of replaced what we thought about with physical firewalls So rather than configuring hardware putting in a data center We're using the cloud and we're using a virtualized network Eventually to configure how we network up together all of our resources and then we use network security groups to filter traffic To and from those Azure resources in that virtual network Within our virtual network security groups are rules and those rules Basically represent how traffic flows back and forth from our resources in our virtual network So we can use a service tag rather than an IP Specific network to actually allow resources to be accessed within Azure if we'd like so a service tag represents a group of IP address prefixes from a given Azure service so Microsoft manages these and Takes care of the making sure that if they're new IP networks, they're part of the service tag That reduces some of your complexity in creating isolation around your network resources So I have a virtual machine created here on Azure. It's just the Linux Ubuntu one It's got a public IP and a virtual network already configured and I've also configured for a network security group And as you can see I don't add any inbound administrative port rules like 22 by default So I've gone ahead and clicked into my inbound security rules and within here I can click add go to a source and you can see these different options But I'm going to pick the service tag now I can pick my source service tag to buy default It's going to be internet, but I don't want to use it You can see all the different services that are available But I'm going to just pick Azure cloud and that's going to allow me to access my VM by the Azure cloud shell Next I'll pick the service that I want to access. There's a different one for all these different administrative service I picked SSH and I've set the priority and now I'll just set a name for the port It's a description and right here. We'll just say service tag for SSH and I'll click add So it'll start creating the security rule and once it's finished creating it You'll get a notification in the Azure portal stating that your created rule is ready to go so I've dropped back into my VM information in the portal and I grabbed the IP address and I'll just SSH in You can see I've got the username the IP address and there we go now I'm able to start working within the cloud shell. I don't have to use a local terminal I can just do everything within our browser and that's it. We've added a network security group rule We're now able to SSH into the Linux VM and I can go on with my life and start working to fix whatever problem I have or configure whatever software So if you want to learn more you can check out the documentation at this link and if you need to reach out to me It's always at J Destro on Twitter. Thanks for watching