{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/",
        "slug": "dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/"
        },
        "title": "Match Connection Monitor's region to its Azure source machines",
        "summary": "The region selected for the monitor constrains which Azure VM and scale-set sources appear in its source selection.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:36+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 241,
        "potentially_affected": "Azure Network Watcher Connection Monitor configurations created through the portal.",
        "dse_recommendation": "Compare the monitor region with source-machine locations before diagnosing a missing endpoint as an access failure.",
        "primary_source": {
            "name": "Create a Connection Monitor - Azure Portal - Azure Network Watcher | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>When creating a connection monitor, the selected region limits the Azure source VMs available. The source picker shows VMs and scale sets bound to that region, grouped by subscription. Connection Monitor also supports on-premises sources with the required monitoring agents.</p>\n<p>Destination endpoints can be Azure resources or other URLs and IP addresses. Microsoft distinguishes the current Connection Monitor from the deprecated classic service and documents Azure Monitor Agent support without a legacy Log Analytics agent dependency. <a href=\"https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify which machine originates each test and which endpoint is the destination. Do not apply a source-region restriction to every destination or mistake an on-premises agent for an Azure VM selection.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends preparing the source-to-destination test matrix before creating monitors. Group Azure sources according to their actual regions and verify agent readiness independently. If a source is absent, check region and resource identity before expanding permissions or recreating the VM. Keep the current monitor design separate from obsolete classic-service procedures.</p>\n<h2>Verification</h2>\n<p>In the approved configuration, compare the selected sources with the planned regional inventory and confirm every required test origin is represented. Exercise a harmless connection test to the intended destination and inspect its source identity in the result. A successful test from one region should not close an unconfigured test from another. Record any missing source and its specific prerequisite for follow-up.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Create a Connection Monitor &#8211; Azure Portal</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nWhen creating a connection monitor, the selected region limits the Azure source VMs available. The source picker shows VMs and scale sets bound to that region, grouped by subscription. Connection Monitor also supports on-premises sources with the required monitoring agents.\nDestination endpoints can be Azure resources or other URLs and IP addresses. Microsoft distinguishes the current Connection Monitor from the deprecated classic service and documents Azure Monitor Agent support without a legacy Log Analytics agent dependency. Microsoft Learn.\nApplicability\nIdentify which machine originates each test and which endpoint is the destination. Do not apply a source-region restriction to every destination or mistake an on-premises agent for an Azure VM selection.\nDSE recommendation\nDSE recommends preparing the source-to-destination test matrix before creating monitors. Group Azure sources according to their actual regions and verify agent readiness independently. If a source is absent, check region and resource identity before expanding permissions or recreating the VM. Keep the current monitor design separate from obsolete classic-service procedures.\nVerification\nIn the approved configuration, compare the selected sources with the planned regional inventory and confirm every required test origin is represented. Exercise a harmless connection test to the intended destination and inspect its source identity in the result. A successful test from one region should not close an unconfigured test from another. Record any missing source and its specific prerequisite for follow-up.\nOfficial references\nMicrosoft Learn: Create a Connection Monitor – Azure Portal. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nWhen creating a connection monitor, the selected region limits the Azure source VMs available. The source picker shows VMs and scale sets bound to that region, grouped by subscription. Connection Monitor also supports on-premises sources with the required monitoring agents.\n\nDestination endpoints can be Azure resources or other URLs and IP addresses. Microsoft distinguishes the current Connection Monitor from the deprecated classic service and documents Azure Monitor Agent support without a legacy Log Analytics agent dependency. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal).\n\n## Applicability\n\nIdentify which machine originates each test and which endpoint is the destination. Do not apply a source-region restriction to every destination or mistake an on-premises agent for an Azure VM selection.\n\n## DSE recommendation\n\nDSE recommends preparing the source-to-destination test matrix before creating monitors. Group Azure sources according to their actual regions and verify agent readiness independently. If a source is absent, check region and resource identity before expanding permissions or recreating the VM. Keep the current monitor design separate from obsolete classic-service procedures.\n\n## Verification\n\nIn the approved configuration, compare the selected sources with the planned regional inventory and confirm every required test origin is represented. Exercise a harmless connection test to the intended destination and inspect its source identity in the result. A successful test from one region should not close an unconfigured test from another. Record any missing source and its specific prerequisite for follow-up.\n\n## Official references\n\n[Microsoft Learn: Create a Connection Monitor – Azure Portal](https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Match Connection Monitor's region to its Azure source machines",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/",
                "headline": "Match Connection Monitor's region to its Azure source machines",
                "description": "The region selected for the monitor constrains which Azure VM and scale-set sources appear in its source selection.",
                "abstract": "The region selected for the monitor constrains which Azure VM and scale-set sources appear in its source selection.",
                "articleBody": "Source facts\nWhen creating a connection monitor, the selected region limits the Azure source VMs available. The source picker shows VMs and scale sets bound to that region, grouped by subscription. Connection Monitor also supports on-premises sources with the required monitoring agents.\nDestination endpoints can be Azure resources or other URLs and IP addresses. Microsoft distinguishes the current Connection Monitor from the deprecated classic service and documents Azure Monitor Agent support without a legacy Log Analytics agent dependency. Microsoft Learn.\nApplicability\nIdentify which machine originates each test and which endpoint is the destination. Do not apply a source-region restriction to every destination or mistake an on-premises agent for an Azure VM selection.\nDSE recommendation\nDSE recommends preparing the source-to-destination test matrix before creating monitors. Group Azure sources according to their actual regions and verify agent readiness independently. If a source is absent, check region and resource identity before expanding permissions or recreating the VM. Keep the current monitor design separate from obsolete classic-service procedures.\nVerification\nIn the approved configuration, compare the selected sources with the planned regional inventory and confirm every required test origin is represented. Exercise a harmless connection test to the intended destination and inspect its source identity in the result. A successful test from one region should not close an unconfigured test from another. Record any missing source and its specific prerequisite for follow-up.\nOfficial references\nMicrosoft Learn: Create a Connection Monitor – Azure Portal. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:25:36+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Match Connection Monitor's region to its Azure source machines"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 241,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create a Connection Monitor - Azure Portal - Azure Network Watcher | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal"
                }
            }
        ]
    }
}