By using a cloud provider, obviously.
Local networks are too dangerous to be trusted.
If its not going through Azure you shouldn’t be allowed to connect to your peer devices.
(/s. if that is needed).