Follow these steps to start managing successfully onboarded VMs in the NSX Enforced Mode.

Table 1. Micro-segmentation workflow for your NSX-managed workload VMs in the NSX Enforced Mode
Task Instructions
To allow inbound access to workload VMs, create distributed firewall (DFW) rules as required. See Default Connectivity Strategy for NSX-Managed Workload VMs in the NSX Enforced Mode.
Group your workload VMs using public cloud tags or NSX-T Data Center tags and set up micro-segmentation. See Set up Micro-segmentation for Workload VMs in the NSX Enforced Mode.

See also: Group VMs using NSX-T Data Center and Public Cloud Tags