GuideInformationCybersecurityIT

Check VM watch's selected authentication method before rotating an Event Hubs credential

Why might changing an Event Hubs connection string not change the authentication VM watch actually uses?

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 2 min read
Executive summary

What you need to know

Why might changing an Event Hubs connection string not change the authentication VM watch actually uses?

Potentially affected

VM watch deployments exporting signals to an authorized Azure Event Hub.

DSE recommendation

Reconcile the configured authentication methods before diagnosing or rotating the output credential.

Source facts

VM watch supports managed identity, SAS tokens and connection strings for Event Hubs output. When several methods are configured, managed identity has the highest priority and a connection string the lowest. For connection-string authentication, the documented value is Base64-encoded and excludes EntityPath; the hub name is configured separately. Startup and heartbeat telemetry require a separate option that is false by default. Microsoft Learn.

Applicability

Use this review while evaluating the VM watch preview’s output configuration or investigating missing events. Separate the chosen authentication method from the kinds of telemetry expected at the destination.

DSE recommendation

Reconcile the configured authentication methods before diagnosing or rotating the output credential. Have the telemetry owner inspect method flags and the intended managed identity without copying secret values into the ticket. Align the configuration with the approved method and confirm the destination namespace and hub. If startup or heartbeat events are required, review that explicit setting rather than treating their absence as proof of authentication failure.

Verification

After an authorized configuration change, inspect incoming event content and VM watch’s own logs. Confirm that the expected VM identity and signal types reach the intended hub. Record which method was actually configured, not simply which credential was most recently edited. Keep any connection-string or SAS material out of ordinary screenshots and retained diagnostics.

Official references

Microsoft Learn: Configure Event Hubs for VM watch. Source reviewed September 9, 2026.

Primary reference

Review the official source

Configure Event Hubs for VM watch - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE