Add ASG support on Azure Firewall
Currently it's not possible to utilize ASGs in the Azure Firewall which limits the possibility of having an autoscaling environment and at the same time limit the network access to only what is necessary by specific resources.
If deploying new resources and adding them into existing ASGs, it would be beneficial to be able to utilize ASGs as source/destination in Azure Firewall as well to remove the need of having to configure IP specific rules each time a new resource is deployed.
Ian Clark commented
Please consider this alongside ASG across vnet peering (including cross tenant) so ASG's can be used globally to define rulesets
Please, this is very useful feature that would allow combination of both worlds, NSG and IP Groups power in Azure Firewall