An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
Hi mani,
The Tenant A traffic is consistent with Azure SQL Managed Instance's automatic internal connectivity tests, which have been running on all SQL Managed Instances since May 2026. These tests originate from reserved private IPs in the MI subnet and run every 10 seconds.
However, Microsoft does not document port 9000 or 10.255.0.x as a specific SQL MI probe endpoint, so I would not treat every connection to that address/port as confirmed Microsoft telemetry based on the logs alone.
For Tenant B, traffic described as coming from external/random sources is a different pattern. 10.255.0.0/8 is private address space, so those sources are likely being represented after NAT, proxying, or internal platform routing rather than being Internet clients directly reaching a 10.255.0.x address.
I would therefore not create a firewall allow rule for 10.255.0.x:9000 solely based on these logs. First identify the actual source interface/IP, next hop, and route in the Azure Firewall logs and Network Watcher before allowing the traffic.