Firewall rules within AWS and Azure have the ability to limit which IP addresses and ranges can access the network. For example, a customer within AWS may choose to create a network access control list (NACL) configured with the IP address of the headquarters to only allow IT from the headquarters' IP address access. Service edge egress IP address needs to be allow-listed by the network administrator.
See NetCloud SASE Points of Presence and Egress IP Addresses for a complete list of NetCloud SASE PoP egress IP addresses.