What you need to know
Review the service path and package location separately when restricting Machine Configuration network access.
Potentially affected
Azure VMs and Arc-enabled servers using Machine Configuration.
DSE recommendation
Record the service connection and every custom package location before approving egress restrictions.
Source facts
For the Azure virtual-network path, Microsoft requires outbound port 443 access and identifies both AzureArcInfrastructure and Storage service tags. Storage is needed because it hosts configuration packages.
Azure VMs using the documented private-link path do not need publicly reachable regional GAS endpoints. However, a custom package at a public Storage or non-Azure URL still needs a reachable, allowed URL. Built-in packages on Arc-enabled servers using private link follow that link without additional server tags.
The Arc built-in-package behavior is documented separately from the Azure VM tagging procedure. Microsoft Learn.
Applicability
Identify whether each target is an Azure VM or an Arc-enabled server, and whether its package is built in or custom. Do not copy one platform’s network assumptions to the other.
DSE recommendation
DSE recommends a two-column access record: service communication and package download. Record the actual package URI from the assignment, its hosting boundary, and the approved route. Review public package dependencies before closing egress. Ask the configuration owner to identify a representative assignment for each distinct package-hosting pattern.
Verification
On approved test machines, compare service reporting with package retrieval and assignment execution. Preserve the target type, assignment, observed destination, and outcome separately. Investigate a successful service connection alongside a failed package download before declaring the restricted design ready.
Official references
Microsoft Learn: Azure Machine Configuration network requirements. Source retrieved September 9, 2026.
Review the official source
Azure Machine Configuration network requirements - Azure Machine Configuration | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE