You must ensure that users are able to access VM0. The solution must satisfy the platform-protection requirements.
What should you do?
Just-in-time (JIT) VM access fails for a virtual machine that sits in a subnet whose route table forces outbound traffic through Azure Firewall as the next hop: the temporary inbound allow rule that JIT opens lets a connection reach the VM's public IP directly, but the return traffic is redirected to the firewall by the user-defined route, and the firewall drops it because it never saw the original inbound session — an asymmetric-routing failure. A network traffic filtering rule or a DNAT rule on the firewall does not fix this, because the problem is the asymmetric return path, not a missing allow or translation rule. Moving VM0 into a subnet that does not have the user-defined route pointing to the firewall removes the asymmetric-routing condition and lets JIT access function normally, while the firewall continues to protect the rest of the environment's traffic, satisfying the platform-protection requirement.
Community Discussion