According to the Office 365 Adapter: Deploying Office 365 Single Sign-On using Windows Azure guide (http://www.microsoft.com/en-us/download/details.aspx?id=38845) you should always use an AD FS Proxy server for publishing AD FS.
How should the AD Proxy server be implemented in Windows Azure?
It is possible to use VNETs, but will this will provide the same security level as traditional perimeter networks in this context?