Well, there are many ways to do this.
1. You can apply an IP to the resource and use the ACLs on the resource in question.
2. You can deploy a Cisco ASA / FTD / or any other firewall supported in Azure and route said traffic through said firewall.
3. You can set up an Azure firewall and route said traffic through the Azure firewall.