Azure requires internet accessible ports to monitor your back end instances
chris408.com
chris408.com
I'm not aware of anyway of this being possible?
The sensitivity of the data or threat risk of the host from these open ports is up for debate and probably should be reverse engineered in any which case.
Could these services be secured by another method that we've missed?
It's undoubtedly bad practice. But surely M$ haven't just left two non-standard HTTP ports open to the internet from all hosted Azure instances?
To reconfirm this, I ran a quick test and saw these ports open by default after I configured an application gateway on my account.