Azure cloud networking -- VNets, NSGs, ExpressRoute, VPN Gateways, Azure Firewalls, Load Balancers, Application Gateways, Route Tables, Network Watcher, Private Endpoints, DNS zones. Use when auditing Azure VNets, troubleshooting hybrid connectivity (ExpressRoute/VPN), inspecting what an NSG currently allows, inspecting firewall policies, or analyzing load balancer health. For CIS Azure Foundations Benchmark compliance scoring, overly-permissive-rule findings, or orphaned NSG detection, use `azure-security-audit` instead.