# Check VM watch's selected authentication method before rotating an Event Hubs credential

> Why might changing an Event Hubs connection string not change the authentication VM watch actually uses?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-039-check-vm-watch-s-selected-authentication-method-before-rotating-an-event-hubs/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:17+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Why might changing an Event Hubs connection string not change the authentication VM watch actually uses?

## Potentially affected

VM watch deployments exporting signals to an authorized Azure Event Hub.

## DSE recommendation

Reconcile the configured authentication methods before diagnosing or rotating the output credential.

## Article

## Source facts

VM watch supports managed identity, SAS tokens and connection strings for Event Hubs output. When several methods are configured, managed identity has the highest priority and a connection string the lowest. For connection-string authentication, the documented value is Base64-encoded and excludes EntityPath; the hub name is configured separately. Startup and heartbeat telemetry require a separate option that is false by default. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/configure-eventhub-vm-watch).

## Applicability

Use this review while evaluating the VM watch preview’s output configuration or investigating missing events. Separate the chosen authentication method from the kinds of telemetry expected at the destination.

## DSE recommendation

Reconcile the configured authentication methods before diagnosing or rotating the output credential. Have the telemetry owner inspect method flags and the intended managed identity without copying secret values into the ticket. Align the configuration with the approved method and confirm the destination namespace and hub. If startup or heartbeat events are required, review that explicit setting rather than treating their absence as proof of authentication failure.

## Verification

After an authorized configuration change, inspect incoming event content and VM watch’s own logs. Confirm that the expected VM identity and signal types reach the intended hub. Record which method was actually configured, not simply which credential was most recently edited. Keep any connection-string or SAS material out of ordinary screenshots and retained diagnostics.

## Official references

[Microsoft Learn: Configure Event Hubs for VM watch](https://learn.microsoft.com/en-us/azure/virtual-machines/configure-eventhub-vm-watch). Source reviewed September 9, 2026.

## Primary reference

- Name: Configure Event Hubs for VM watch - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/configure-eventhub-vm-watch
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check VM watch's selected authentication method before rotating an Event Hubs credential,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-039-check-vm-watch-s-selected-authentication-method-before-rotating-an-event-hubs/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
