{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/",
        "slug": "dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/"
        },
        "title": "Test boot-diagnostics capture separately from an operator's ability to view it",
        "summary": "Which storage paths should be checked when Azure boot diagnostics are missing or inaccessible?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:31:27+00:00",
        "modified_at": "2026-09-10T00:32:00+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 261,
        "potentially_affected": "Operators using Azure VM boot diagnostics with managed or custom storage.",
        "dse_recommendation": "Test platform capture and authorized operator viewing as two separate checks before relying on boot diagnostics.",
        "primary_source": {
            "name": "Azure boot diagnostics - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/boot-diagnostics",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure boot diagnostics collects serial output and screenshots for investigating startup failures. With firewall-protected custom storage, Microsoft requires access for Azure to publish that evidence and separate firewall allowances for the operator&#8217;s viewing network. Viewing also requires the appropriate read and view permissions. The custom account must share the VM&#8217;s region and subscription. Managed boot diagnostics offers no configurable retention period and overwrites logs after their total size exceeds 1 GB. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/boot-diagnostics\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify whether each VM uses managed or custom diagnostic storage before investigating an empty view. For custom storage, record the selected account and the approved support workstation&#8217;s network. Check the source&#8217;s supported account types and VM limitations instead of copying a storage policy from unrelated evidence systems.</p>\n<h2>DSE recommendation</h2>\n<p>Test platform capture and authorized operator viewing as two separate checks before relying on boot diagnostics. Assign the VM owner to identify an expected startup observation and the storage owner to review its access path. Establish a deliberate preservation step for evidence needed beyond the live troubleshooting session. Keep that decision separate from normal application-log retention.</p>\n<h2>Verification</h2>\n<p>During an approved diagnostic exercise, confirm that a current screenshot and serial output can be retrieved by the intended responder. Compare an authorized viewing path with an intentionally unapproved one, without widening production access simply to make the test pass. Record the VM, storage mode, observation time, and retrieval result. Investigate whether a missing artifact was never captured or merely could not be read before declaring the diagnostic feature unavailable.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/boot-diagnostics\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Azure boot diagnostics</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nAzure boot diagnostics collects serial output and screenshots for investigating startup failures. With firewall-protected custom storage, Microsoft requires access for Azure to publish that evidence and separate firewall allowances for the operator’s viewing network. Viewing also requires the appropriate read and view permissions. The custom account must share the VM’s region and subscription. Managed boot diagnostics offers no configurable retention period and overwrites logs after their total size exceeds 1 GB. Microsoft Learn.\nApplicability\nIdentify whether each VM uses managed or custom diagnostic storage before investigating an empty view. For custom storage, record the selected account and the approved support workstation’s network. Check the source’s supported account types and VM limitations instead of copying a storage policy from unrelated evidence systems.\nDSE recommendation\nTest platform capture and authorized operator viewing as two separate checks before relying on boot diagnostics. Assign the VM owner to identify an expected startup observation and the storage owner to review its access path. Establish a deliberate preservation step for evidence needed beyond the live troubleshooting session. Keep that decision separate from normal application-log retention.\nVerification\nDuring an approved diagnostic exercise, confirm that a current screenshot and serial output can be retrieved by the intended responder. Compare an authorized viewing path with an intentionally unapproved one, without widening production access simply to make the test pass. Record the VM, storage mode, observation time, and retrieval result. Investigate whether a missing artifact was never captured or merely could not be read before declaring the diagnostic feature unavailable.\nOfficial references\nMicrosoft Learn: Azure boot diagnostics. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure boot diagnostics collects serial output and screenshots for investigating startup failures. With firewall-protected custom storage, Microsoft requires access for Azure to publish that evidence and separate firewall allowances for the operator’s viewing network. Viewing also requires the appropriate read and view permissions. The custom account must share the VM’s region and subscription. Managed boot diagnostics offers no configurable retention period and overwrites logs after their total size exceeds 1 GB. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/boot-diagnostics).\n\n## Applicability\n\nIdentify whether each VM uses managed or custom diagnostic storage before investigating an empty view. For custom storage, record the selected account and the approved support workstation’s network. Check the source’s supported account types and VM limitations instead of copying a storage policy from unrelated evidence systems.\n\n## DSE recommendation\n\nTest platform capture and authorized operator viewing as two separate checks before relying on boot diagnostics. Assign the VM owner to identify an expected startup observation and the storage owner to review its access path. Establish a deliberate preservation step for evidence needed beyond the live troubleshooting session. Keep that decision separate from normal application-log retention.\n\n## Verification\n\nDuring an approved diagnostic exercise, confirm that a current screenshot and serial output can be retrieved by the intended responder. Compare an authorized viewing path with an intentionally unapproved one, without widening production access simply to make the test pass. Record the VM, storage mode, observation time, and retrieval result. Investigate whether a missing artifact was never captured or merely could not be read before declaring the diagnostic feature unavailable.\n\n## Official references\n\n[Microsoft Learn: Azure boot diagnostics](https://learn.microsoft.com/en-us/azure/virtual-machines/boot-diagnostics). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Test boot-diagnostics capture separately from an operator's ability to view it",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/",
                "headline": "Test boot-diagnostics capture separately from an operator's ability to view it",
                "description": "Which storage paths should be checked when Azure boot diagnostics are missing or inaccessible?",
                "abstract": "Which storage paths should be checked when Azure boot diagnostics are missing or inaccessible?",
                "articleBody": "Source facts\nAzure boot diagnostics collects serial output and screenshots for investigating startup failures. With firewall-protected custom storage, Microsoft requires access for Azure to publish that evidence and separate firewall allowances for the operator’s viewing network. Viewing also requires the appropriate read and view permissions. The custom account must share the VM’s region and subscription. Managed boot diagnostics offers no configurable retention period and overwrites logs after their total size exceeds 1 GB. Microsoft Learn.\nApplicability\nIdentify whether each VM uses managed or custom diagnostic storage before investigating an empty view. For custom storage, record the selected account and the approved support workstation’s network. Check the source’s supported account types and VM limitations instead of copying a storage policy from unrelated evidence systems.\nDSE recommendation\nTest platform capture and authorized operator viewing as two separate checks before relying on boot diagnostics. Assign the VM owner to identify an expected startup observation and the storage owner to review its access path. Establish a deliberate preservation step for evidence needed beyond the live troubleshooting session. Keep that decision separate from normal application-log retention.\nVerification\nDuring an approved diagnostic exercise, confirm that a current screenshot and serial output can be retrieved by the intended responder. Compare an authorized viewing path with an intentionally unapproved one, without widening production access simply to make the test pass. Record the VM, storage mode, observation time, and retrieval result. Investigate whether a missing artifact was never captured or merely could not be read before declaring the diagnostic feature unavailable.\nOfficial references\nMicrosoft Learn: Azure boot diagnostics. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:31:27+00:00",
                "dateModified": "2026-09-10T00:32:00+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-029-test-boot-diagnostics-capture-separately-from-an-operator-s-ability-to-view-it/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Test boot-diagnostics capture separately from an operator's ability to view it"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 261,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Azure boot diagnostics - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/boot-diagnostics"
                }
            }
        ]
    }
}