Effective resolution: walks rules in Azure priority order, first-match wins.
A higher-priority Deny that neutralizes a permissive Allow does not raise a false positive. Service tags (VirtualNetwork / AzureLoadBalancer / named ASGs) are correctly treated as non-public.
0.0.0.0/1 split-range covered.