# Treat VM watch's outbound-disabled attribute as a test-eligibility declaration

> Does setting OutboundConnectivityDisabled in VM watch enforce a network restriction?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-040-treat-vm-watch-s-outbound-disabled-attribute-as-a-test-eligibility-declaration/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:16+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Does setting OutboundConnectivityDisabled in VM watch enforce a network restriction?

## Potentially affected

VM watch deployments aligning in-guest checks with an intentionally restricted outbound network design.

## DSE recommendation

Compare the declared VM watch environment with the actual network restriction before suppressing a check.

## Article

## Source facts

VM watch’s environmentAttributes help determine whether signals are eligible to execute. In the documented outbound-disabled example, setting OutboundConnectivityDisabled marks outbound-network-related signal execution ineligible. The source presents that value as information about an already disabled outbound path. Separately, signalFilters can enable optional collectors or disable named or tagged signals; only core-group signals are enabled by default. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/configure-vm-watch).

## Applicability

Use this distinction during a VM watch preview evaluation when a restricted VM produces an unexpected or absent check. Keep the monitoring declaration separate from the network configuration it is intended to describe.

## DSE recommendation

Compare the declared VM watch environment with the actual network restriction before suppressing a check. Have the network and monitoring owners agree which checks are meaningful for the VM’s actual design. Verify the restriction through its authorized network controls, then review whether the declared attribute accurately represents it. Do not use an ineligible-check result as evidence that outbound traffic has been blocked.

## Verification

In a controlled environment, inspect the configured attribute, collector filters and resulting signal eligibility together. Test the permitted and prohibited network behavior through the approved network-validation process independently. If the declaration and actual connectivity disagree, correct the responsible configuration before accepting the monitoring result. Preserve the reason for each intentionally excluded check so a later owner can distinguish policy-driven omission from an unexpected collection failure.

## Official references

[Microsoft Learn: Configure VM watch](https://learn.microsoft.com/en-us/azure/virtual-machines/configure-vm-watch). Source reviewed September 9, 2026.

## Primary reference

- Name: Configure VM watch - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/configure-vm-watch
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat VM watch's outbound-disabled attribute as a test-eligibility declaration,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-040-treat-vm-watch-s-outbound-disabled-attribute-as-a-test-eligibility-declaration/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
