The Azure DevOps agent only talks over HTTPS to Azure DevOps. The communication is one-way: The agent talks to Azure DevOps. Azure DevOps does not open up a connection to the machine.
As long as the machines can talk to Azure DevOps, you should be fine.
There may be additional configuration necessary depending on what you want to actually do with the machine from a deployment perspective, but there's no way anyone can help you with that because you didn't mention what a deployment to that machine may look like.
与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…