Using Resource Manager model:
When I create an Azure VM, access to the RDP port to the public internet is enabled by default. There is no Network Security Group is assigned to the VM.
I am trying to understand where and how is the RDP port 3389 access rule is defined?
Update 1 @Jack Zeng: Per below screenshot, when an ARM VM is created, there is no "Network Security Group" is assigned to it. That is why RDP availability to the public internet seems to be a "Magic" and I am asking this question.