Hi ,
Thanks for reaching out to Microsoft Q&A.
Even though you’re already running a VM level backup, the SQL in guest backup extension requires connectivity to specific Azure services (Backup, Storage, and Microsoft Entra ID) in order to discover databases, configure backup policies, run backups, and do restores. If your VM’s networking is locked down or you’re using custom NSGs/firewalls, you’ll need to explicitly allow (or tag) outbound traffic to those services. Without proper connectivity, the in guest SQL backup extension won’t be able to do its job (db discovery, backup, and restore operations might fail).
Please feel free to click the 'Upvote' (Thumbs-up) button and 'Accept as Answer'. This helps the community by allowing others with similar queries to easily find the solution.