GuideInformationCybersecurityIT

Choose one MSP configuration representation for each metadata service

Can an MSP metadata endpoint use an inline mode and a linked access-control profile together?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Can an MSP metadata endpoint use an inline mode and a linked access-control profile together?

Potentially affected

Owners configuring Metadata Security Protocol on a supported Azure VM or scale set.

DSE recommendation

Choose either inline mode or a linked profile separately for each metadata service.

Source facts

MSP configuration requires API version 2024-03-01 or later. For an individual metadata service, an inline mode and a linked access-control profile are mutually exclusive. Inline configuration does not provide customization; linked profiles do. Audit mode forwards requests while logging the authorization result, whereas Enforce mode rejects unauthorized callers and requires signed requests at the service. Microsoft Learn.

Applicability

Review the effective configuration for each endpoint, not just the presence of the VM’s MSP enabled flag. This is a configuration-shape and enforcement-state check for an otherwise supported workload, not a substitute for platform compatibility review.

DSE recommendation

Choose either inline mode or a linked profile separately for each metadata service. Maintain a clear mapping from each endpoint to its chosen representation, profile version where applicable, and intended behavior. Before changing that choice, have the deployment owner inspect the complete desired resource model for stale properties left by a previous configuration. Preserve the intended observation stage and the later enforcement decision as separate change records.

Verification

Check the submitted resource configuration and the resulting settings together. In a controlled test, compare an authorized request with an intentionally unauthorized request and inspect the associated local audit evidence. Do not interpret an audit entry as proof that the request was blocked. Resolve any mismatch between the declared mode and observed behavior before expanding deployment.

Official references

Microsoft Learn: MSP feature configuration. Source reviewed September 9, 2026.

Primary reference

Review the official source

MSP Feature Configuration - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE