{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/",
        "slug": "dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/"
        },
        "title": "Do not treat a successful Azure Firewall packet capture as coverage of every instance",
        "summary": "The documented success threshold is captures from at least half of the firewall's underlying compute instances.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:20+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 247,
        "potentially_affected": "Azure Firewall packet-capture investigations with the required Management NIC enabled.",
        "dse_recommendation": "Record capture coverage limits, filters and stop conditions before drawing a negative traffic conclusion.",
        "primary_source": {
            "name": "Use Packet Capture to Troubleshoot Azure Firewall | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/firewall/packet-capture",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure reports packet-capture success when at least half of the firewall&#8217;s underlying compute instances provide captures. The portal does not identify which instances contributed. Success therefore does not establish complete instance coverage.</p>\n<p>A capture requires at least one filter and records matching traffic in both directions. Both a packet maximum and a time limit are required; whichever is reached first stops collection. The documented feature also requires an enabled Management NIC. <a href=\"https://learn.microsoft.com/en-us/azure/firewall/packet-capture\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review the actual capture prerequisites, approved storage destination, filters and diagnostic objective before collection. Keep capture-data access and retention under the organization&#8217;s security controls; this article is not a blanket approval for the storage settings in a tutorial.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends preserving the success status together with its documented coverage limit. Describe a missing packet as absent from the collected evidence, not proof that no firewall instance processed it. Review whether filters and stop conditions were capable of observing the traffic in question before planning further collection. Broaden collection only with appropriate approval for the additional data.</p>\n<h2>Verification</h2>\n<p>Use a controlled test flow to check the intended capture filter and inspect the resulting files and timing. Compare the observed traffic with the selected protocol and stop limits. Record any unknown instance coverage explicitly and corroborate the investigation through other approved evidence where needed. Do not silently upgrade a successful collection status into a complete traffic history.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/firewall/packet-capture\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use Packet Capture to Troubleshoot Azure Firewall</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nAzure reports packet-capture success when at least half of the firewall’s underlying compute instances provide captures. The portal does not identify which instances contributed. Success therefore does not establish complete instance coverage.\nA capture requires at least one filter and records matching traffic in both directions. Both a packet maximum and a time limit are required; whichever is reached first stops collection. The documented feature also requires an enabled Management NIC. Microsoft Learn.\nApplicability\nReview the actual capture prerequisites, approved storage destination, filters and diagnostic objective before collection. Keep capture-data access and retention under the organization’s security controls; this article is not a blanket approval for the storage settings in a tutorial.\nDSE recommendation\nDSE recommends preserving the success status together with its documented coverage limit. Describe a missing packet as absent from the collected evidence, not proof that no firewall instance processed it. Review whether filters and stop conditions were capable of observing the traffic in question before planning further collection. Broaden collection only with appropriate approval for the additional data.\nVerification\nUse a controlled test flow to check the intended capture filter and inspect the resulting files and timing. Compare the observed traffic with the selected protocol and stop limits. Record any unknown instance coverage explicitly and corroborate the investigation through other approved evidence where needed. Do not silently upgrade a successful collection status into a complete traffic history.\nOfficial references\nMicrosoft Learn: Use Packet Capture to Troubleshoot Azure Firewall. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure reports packet-capture success when at least half of the firewall’s underlying compute instances provide captures. The portal does not identify which instances contributed. Success therefore does not establish complete instance coverage.\n\nA capture requires at least one filter and records matching traffic in both directions. Both a packet maximum and a time limit are required; whichever is reached first stops collection. The documented feature also requires an enabled Management NIC. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/firewall/packet-capture).\n\n## Applicability\n\nReview the actual capture prerequisites, approved storage destination, filters and diagnostic objective before collection. Keep capture-data access and retention under the organization’s security controls; this article is not a blanket approval for the storage settings in a tutorial.\n\n## DSE recommendation\n\nDSE recommends preserving the success status together with its documented coverage limit. Describe a missing packet as absent from the collected evidence, not proof that no firewall instance processed it. Review whether filters and stop conditions were capable of observing the traffic in question before planning further collection. Broaden collection only with appropriate approval for the additional data.\n\n## Verification\n\nUse a controlled test flow to check the intended capture filter and inspect the resulting files and timing. Compare the observed traffic with the selected protocol and stop limits. Record any unknown instance coverage explicitly and corroborate the investigation through other approved evidence where needed. Do not silently upgrade a successful collection status into a complete traffic history.\n\n## Official references\n\n[Microsoft Learn: Use Packet Capture to Troubleshoot Azure Firewall](https://learn.microsoft.com/en-us/azure/firewall/packet-capture). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not treat a successful Azure Firewall packet capture as coverage of every instance",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/",
                "headline": "Do not treat a successful Azure Firewall packet capture as coverage of every instance",
                "description": "The documented success threshold is captures from at least half of the firewall's underlying compute instances.",
                "abstract": "The documented success threshold is captures from at least half of the firewall's underlying compute instances.",
                "articleBody": "Source facts\nAzure reports packet-capture success when at least half of the firewall’s underlying compute instances provide captures. The portal does not identify which instances contributed. Success therefore does not establish complete instance coverage.\nA capture requires at least one filter and records matching traffic in both directions. Both a packet maximum and a time limit are required; whichever is reached first stops collection. The documented feature also requires an enabled Management NIC. Microsoft Learn.\nApplicability\nReview the actual capture prerequisites, approved storage destination, filters and diagnostic objective before collection. Keep capture-data access and retention under the organization’s security controls; this article is not a blanket approval for the storage settings in a tutorial.\nDSE recommendation\nDSE recommends preserving the success status together with its documented coverage limit. Describe a missing packet as absent from the collected evidence, not proof that no firewall instance processed it. Review whether filters and stop conditions were capable of observing the traffic in question before planning further collection. Broaden collection only with appropriate approval for the additional data.\nVerification\nUse a controlled test flow to check the intended capture filter and inspect the resulting files and timing. Compare the observed traffic with the selected protocol and stop limits. Record any unknown instance coverage explicitly and corroborate the investigation through other approved evidence where needed. Do not silently upgrade a successful collection status into a complete traffic history.\nOfficial references\nMicrosoft Learn: Use Packet Capture to Troubleshoot Azure Firewall. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:22:20+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not treat a successful Azure Firewall packet capture as coverage of every instance"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 247,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use Packet Capture to Troubleshoot Azure Firewall | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/firewall/packet-capture"
                }
            }
        ]
    }
}