Apart from load balancers, the source for inbound rules should not be open to all IPs or ports for production scenarios. For other ports such as RDP/SSH, access should be allowed from the Jump Server/Bastion Host. All rules in an SG are evaluated before allowing any traffic.