# Inventory every autoscale webhook instead of trusting the first portal entry

> Can the autoscale notification pane hide additional configured webhook destinations?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-347-inventory-every-autoscale-webhook-instead-of-trusting-the-first-portal-entry/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:09+00:00
- Modified: 2026-09-10T01:40:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Checklist
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can the autoscale notification pane hide additional configured webhook destinations?

## Potentially affected

Azure Monitor autoscale settings with webhook notifications, particularly settings managed through multiple tools.

## DSE recommendation

Review the complete serialized notification configuration before approving or removing an autoscale callback destination.

## Article

## Source facts

Azure autoscale supports multiple webhook notifications, but Microsoft states that the portal displays only the first webhook even though the additional entries are visible in JSON. The documented configuration exposes a webhooks collection and allows optional properties for each receiver. Its webhook URI requirement is HTTPS. A single visible destination therefore does not establish that only one callback is configured. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/autoscale/autoscale-webhook-email).

## Applicability

Use this review when an autoscale setting has been maintained through the portal, command-line tools, or templates. Identify the specific setting and its target resource. Treat notification destinations separately from the scaling rules themselves; this article does not change capacity or threshold decisions.

## DSE recommendation

Review the complete serialized notification configuration before approving or removing an autoscale callback destination. Reconcile every receiver with its owner and operational purpose, including entries that are absent from the portal’s first view. Inspect custom properties and authentication configuration without copying secrets into a general inventory. Ask the owner to resolve unknown endpoints before declaring the destination review complete.

## Verification

Compare the full configuration before and after an approved edit. Confirm that the intended receiver changed and that unrelated callback entries remain as approved. During a controlled notification exercise, reconcile observed receiver activity with the complete list. Retain a redacted configuration comparison and owner decisions; a screenshot of one webhook is insufficient evidence for this particular inventory check.

## Official references

[Microsoft Learn: Autoscale email and webhook notifications](https://learn.microsoft.com/en-us/azure/azure-monitor/autoscale/autoscale-webhook-email). Source reviewed September 9, 2026.

## Primary reference

- Name: Use autoscale to send email and webhook alert notifications - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/autoscale/autoscale-webhook-email
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Inventory every autoscale webhook instead of trusting the first portal entry,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-347-inventory-every-autoscale-webhook-instead-of-trusting-the-first-portal-entry/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
