Check each action type before calling an Azure Monitor action group perimeter-isolated

Does a regional action group place every notification action inside a Network Security Perimeter?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureChecklist · 2 min read
Executive summary

What you need to know

Does a regional action group place every notification action inside a Network Security Perimeter?

Potentially affected

Azure Monitor action groups evaluated for Network Security Perimeter in supported public-cloud regions.

DSE recommendation

Review action-group location and every configured action type before approving the notification path as perimeter-controlled.

Source facts

Azure Monitor Network Security Perimeter support requires regional action groups; global groups default to public network access. Event Hub is the only documented supported action type, and other action types also default to public network access. The perimeter does not remove authentication or authorization requirements for communication inside it. Microsoft lists availability in public-cloud regions where Azure Monitor is supported. Microsoft Learn.

Applicability

Inventory the actual action-group resource and its actions before relying on a perimeter association. Treat each receiving endpoint as a separate path to review. This brief does not assert that a global group or a non-Event-Hub action becomes private merely because related monitoring resources belong to a perimeter.

DSE recommendation

Review action-group location and every configured action type before approving the notification path as perimeter-controlled. Have the monitoring and network owners identify any unsupported path in the design. If a different delivery arrangement is required, evaluate it explicitly rather than assuming the perimeter covers all existing notifications. Preserve required operational alerting while the replacement is tested. Review the receiving resource’s access permissions independently from its network association.

Verification

For an approved regional Event Hub action, inspect the resource association and perform a controlled notification test to the intended receiver. Confirm that expected delivery succeeds under the chosen access rules. Separately record every action that continues over its documented public-network path and obtain owner acceptance for that boundary. Keep evidence of delivery and evidence of network control distinct; receiving a test alert alone does not establish where that action is enforced.

Official references

Microsoft Learn: Configure Azure Monitor with Network Security Perimeter. Source reviewed September 9, 2026.

Primary reference

Review the official source

Configure Azure Monitor with Network Security Perimeter - Azure Monitor | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE