{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/",
        "slug": "dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/"
        },
        "title": "Check each action type before calling an Azure Monitor action group perimeter-isolated",
        "summary": "Does a regional action group place every notification action inside a Network Security Perimeter?",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:45+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 269,
        "potentially_affected": "Azure Monitor action groups evaluated for Network Security Perimeter in supported public-cloud regions.",
        "dse_recommendation": "Review action-group location and every configured action type before approving the notification path as perimeter-controlled.",
        "primary_source": {
            "name": "Configure Azure Monitor with Network Security Perimeter - Azure Monitor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/network-security-perimeter",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure Monitor Network Security Perimeter support requires regional action groups; global groups default to public network access. Event Hub is the only documented supported action type, and other action types also default to public network access. The perimeter does not remove authentication or authorization requirements for communication inside it. Microsoft lists availability in public-cloud regions where Azure Monitor is supported. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/network-security-perimeter\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Inventory the actual action-group resource and its actions before relying on a perimeter association. Treat each receiving endpoint as a separate path to review. This brief does not assert that a global group or a non-Event-Hub action becomes private merely because related monitoring resources belong to a perimeter.</p>\n<h2>DSE recommendation</h2>\n<p>Review action-group location and every configured action type before approving the notification path as perimeter-controlled. Have the monitoring and network owners identify any unsupported path in the design. If a different delivery arrangement is required, evaluate it explicitly rather than assuming the perimeter covers all existing notifications. Preserve required operational alerting while the replacement is tested. Review the receiving resource&#8217;s access permissions independently from its network association.</p>\n<h2>Verification</h2>\n<p>For an approved regional Event Hub action, inspect the resource association and perform a controlled notification test to the intended receiver. Confirm that expected delivery succeeds under the chosen access rules. Separately record every action that continues over its documented public-network path and obtain owner acceptance for that boundary. Keep evidence of delivery and evidence of network control distinct; receiving a test alert alone does not establish where that action is enforced.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/network-security-perimeter\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Azure Monitor with Network Security Perimeter</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nAzure Monitor Network Security Perimeter support requires regional action groups; global groups default to public network access. Event Hub is the only documented supported action type, and other action types also default to public network access. The perimeter does not remove authentication or authorization requirements for communication inside it. Microsoft lists availability in public-cloud regions where Azure Monitor is supported. Microsoft Learn.\nApplicability\nInventory the actual action-group resource and its actions before relying on a perimeter association. Treat each receiving endpoint as a separate path to review. This brief does not assert that a global group or a non-Event-Hub action becomes private merely because related monitoring resources belong to a perimeter.\nDSE recommendation\nReview action-group location and every configured action type before approving the notification path as perimeter-controlled. Have the monitoring and network owners identify any unsupported path in the design. If a different delivery arrangement is required, evaluate it explicitly rather than assuming the perimeter covers all existing notifications. Preserve required operational alerting while the replacement is tested. Review the receiving resource’s access permissions independently from its network association.\nVerification\nFor an approved regional Event Hub action, inspect the resource association and perform a controlled notification test to the intended receiver. Confirm that expected delivery succeeds under the chosen access rules. Separately record every action that continues over its documented public-network path and obtain owner acceptance for that boundary. Keep evidence of delivery and evidence of network control distinct; receiving a test alert alone does not establish where that action is enforced.\nOfficial references\nMicrosoft Learn: Configure Azure Monitor with Network Security Perimeter. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure Monitor Network Security Perimeter support requires regional action groups; global groups default to public network access. Event Hub is the only documented supported action type, and other action types also default to public network access. The perimeter does not remove authentication or authorization requirements for communication inside it. Microsoft lists availability in public-cloud regions where Azure Monitor is supported. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/network-security-perimeter).\n\n## Applicability\n\nInventory the actual action-group resource and its actions before relying on a perimeter association. Treat each receiving endpoint as a separate path to review. This brief does not assert that a global group or a non-Event-Hub action becomes private merely because related monitoring resources belong to a perimeter.\n\n## DSE recommendation\n\nReview action-group location and every configured action type before approving the notification path as perimeter-controlled. Have the monitoring and network owners identify any unsupported path in the design. If a different delivery arrangement is required, evaluate it explicitly rather than assuming the perimeter covers all existing notifications. Preserve required operational alerting while the replacement is tested. Review the receiving resource’s access permissions independently from its network association.\n\n## Verification\n\nFor an approved regional Event Hub action, inspect the resource association and perform a controlled notification test to the intended receiver. Confirm that expected delivery succeeds under the chosen access rules. Separately record every action that continues over its documented public-network path and obtain owner acceptance for that boundary. Keep evidence of delivery and evidence of network control distinct; receiving a test alert alone does not establish where that action is enforced.\n\n## Official references\n\n[Microsoft Learn: Configure Azure Monitor with Network Security Perimeter](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/network-security-perimeter). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check each action type before calling an Azure Monitor action group perimeter-isolated",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/",
                "headline": "Check each action type before calling an Azure Monitor action group perimeter-isolated",
                "description": "Does a regional action group place every notification action inside a Network Security Perimeter?",
                "abstract": "Does a regional action group place every notification action inside a Network Security Perimeter?",
                "articleBody": "Source facts\nAzure Monitor Network Security Perimeter support requires regional action groups; global groups default to public network access. Event Hub is the only documented supported action type, and other action types also default to public network access. The perimeter does not remove authentication or authorization requirements for communication inside it. Microsoft lists availability in public-cloud regions where Azure Monitor is supported. Microsoft Learn.\nApplicability\nInventory the actual action-group resource and its actions before relying on a perimeter association. Treat each receiving endpoint as a separate path to review. This brief does not assert that a global group or a non-Event-Hub action becomes private merely because related monitoring resources belong to a perimeter.\nDSE recommendation\nReview action-group location and every configured action type before approving the notification path as perimeter-controlled. Have the monitoring and network owners identify any unsupported path in the design. If a different delivery arrangement is required, evaluate it explicitly rather than assuming the perimeter covers all existing notifications. Preserve required operational alerting while the replacement is tested. Review the receiving resource’s access permissions independently from its network association.\nVerification\nFor an approved regional Event Hub action, inspect the resource association and perform a controlled notification test to the intended receiver. Confirm that expected delivery succeeds under the chosen access rules. Separately record every action that continues over its documented public-network path and obtain owner acceptance for that boundary. Keep evidence of delivery and evidence of network control distinct; receiving a test alert alone does not establish where that action is enforced.\nOfficial references\nMicrosoft Learn: Configure Azure Monitor with Network Security Perimeter. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:25:45+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-371-check-each-action-type-before-calling-an-azure-monitor-action-group-perimeter/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check each action type before calling an Azure Monitor action group perimeter-isolated"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Checklist",
                    "Information priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 269,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Azure Monitor with Network Security Perimeter - Azure Monitor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/network-security-perimeter"
                }
            }
        ]
    }
}