This set of Azure Network Security Group inbound rules came from a "best practice" blog.
I understand this to mean there isn't any way for any network traffic to pass the "DropAll" rule and reach the "AllowVNetInbound" rule. Do I understand that correctly?
I can imagine a few cases where you might want to deny all inbound traffic from the vNet, but I can't imagine why that would be considered a best practice. (I understand best practice to mean always do this unless there's a seriously compelling reason not to.) What am I missing here?