# Separate Machine Configuration service access from custom package access

> Review the service path and package location separately when restricting Machine Configuration network access.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-013-separate-machine-configuration-service-access-from-custom-package-access/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:43+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Review the service path and package location separately when restricting Machine Configuration network access.

## Potentially affected

Azure VMs and Arc-enabled servers using Machine Configuration.

## DSE recommendation

Record the service connection and every custom package location before approving egress restrictions.

## Article

## Source facts

For the Azure virtual-network path, Microsoft requires outbound port 443 access and identifies both AzureArcInfrastructure and Storage service tags. Storage is needed because it hosts configuration packages.

Azure VMs using the documented private-link path do not need publicly reachable regional GAS endpoints. However, a custom package at a public Storage or non-Azure URL still needs a reachable, allowed URL. Built-in packages on Arc-enabled servers using private link follow that link without additional server tags.

The Arc built-in-package behavior is documented separately from the Azure VM tagging procedure. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/03-network-requirements).

## Applicability

Identify whether each target is an Azure VM or an Arc-enabled server, and whether its package is built in or custom. Do not copy one platform’s network assumptions to the other.

## DSE recommendation

DSE recommends a two-column access record: service communication and package download. Record the actual package URI from the assignment, its hosting boundary, and the approved route. Review public package dependencies before closing egress. Ask the configuration owner to identify a representative assignment for each distinct package-hosting pattern.

## Verification

On approved test machines, compare service reporting with package retrieval and assignment execution. Preserve the target type, assignment, observed destination, and outcome separately. Investigate a successful service connection alongside a failed package download before declaring the restricted design ready.

## Official references

[Microsoft Learn: Azure Machine Configuration network requirements](https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/03-network-requirements). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure Machine Configuration network requirements - Azure Machine Configuration | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/03-network-requirements
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate Machine Configuration service access from custom package access,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-013-separate-machine-configuration-service-access-from-custom-package-access/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
