Treat VM watch's outbound-disabled attribute as a test-eligibility declaration

Does setting OutboundConnectivityDisabled in VM watch enforce a network restriction?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Does setting OutboundConnectivityDisabled in VM watch enforce a network restriction?

Potentially affected

VM watch deployments aligning in-guest checks with an intentionally restricted outbound network design.

DSE recommendation

Compare the declared VM watch environment with the actual network restriction before suppressing a check.

Source facts

VM watch’s environmentAttributes help determine whether signals are eligible to execute. In the documented outbound-disabled example, setting OutboundConnectivityDisabled marks outbound-network-related signal execution ineligible. The source presents that value as information about an already disabled outbound path. Separately, signalFilters can enable optional collectors or disable named or tagged signals; only core-group signals are enabled by default. Microsoft Learn.

Applicability

Use this distinction during a VM watch preview evaluation when a restricted VM produces an unexpected or absent check. Keep the monitoring declaration separate from the network configuration it is intended to describe.

DSE recommendation

Compare the declared VM watch environment with the actual network restriction before suppressing a check. Have the network and monitoring owners agree which checks are meaningful for the VM’s actual design. Verify the restriction through its authorized network controls, then review whether the declared attribute accurately represents it. Do not use an ineligible-check result as evidence that outbound traffic has been blocked.

Verification

In a controlled environment, inspect the configured attribute, collector filters and resulting signal eligibility together. Test the permitted and prohibited network behavior through the approved network-validation process independently. If the declaration and actual connectivity disagree, correct the responsible configuration before accepting the monitoring result. Preserve the reason for each intentionally excluded check so a later owner can distinguish policy-driven omission from an unexpected collection failure.

Official references

Microsoft Learn: Configure VM watch. Source reviewed September 9, 2026.

Primary reference

Review the official source

Configure VM watch - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE