All SSH ports on any machine within Azure should have either CU subnets as a filter or the individual hosts IP as a /32 CIDR block. Under no reason should anyone on the internet should be able to view an OpenSSH port without using VPN or use your individual static IP address.
Learn more about SSH in Azure here: https://docs.microsoft.com/en-us/azure/virtual-machines/linux/ssh-from-windows