Well, there are many ways to do this.
1. You can apply an IP to the resource and use the ACLs on the resource in question.
2. You can deploy a Cisco ASA / FTD / or any other firewall supported in Azure and route said traffic through said firewall.
3. You can set up an Azure firewall and route said traffic through the Azure firewall.
If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.