What you need to know
What must change in an action group when the key saved for its Azure Function endpoint is rotated?
Potentially affected
Azure Monitor action groups invoking Azure Functions through a saved endpoint and access key.
DSE recommendation
Include recreation and testing of the function action in the approved key-rotation procedure.
Source facts
For the documented key-based Function action, Azure Monitor saves the HTTP-trigger endpoint and its access key in the action definition. Microsoft instructs administrators to remove and recreate that action after changing the Function key. The endpoint must accept HTTP POST. Microsoft Learn.
An action group must be saved before testing, including after edits. Its test provides Success or Failed status and error details when unsuccessful. Closing the running test window stops the test and prevents results from being returned. Microsoft Learn.
Applicability
Use this procedure for Azure Monitor action groups invoking Azure Functions through a saved endpoint and access key. It is not a procedure for the separately documented managed-identity preview. Identify the authentication actually configured before choosing a rotation path.
DSE recommendation
DSE recommends adding the dependent function action to the key owner’s rotation record. Arrange a safe test payload and notify the workflow owner before recreating it. Keep secrets out of tickets and screenshots; record only the action identity, change reference and outcome. Do not assume that changing the Function key automatically updates an existing action definition.
Verification
Save the replacement action, run the selected action-group test and leave its result view open. Correlate the reported outcome with the Function owner’s observed invocation and intended downstream result. Retain sanitized errors if either observation fails, and keep the change open until the two sides agree.
Official references
Review the official source
Create and manage action groups in Azure Monitor - Azure Monitor | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE