# Match Connection Monitor's region to its Azure source machines

> The region selected for the monitor constrains which Azure VM and scale-set sources appear in its source selection.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:36+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

The region selected for the monitor constrains which Azure VM and scale-set sources appear in its source selection.

## Potentially affected

Azure Network Watcher Connection Monitor configurations created through the portal.

## DSE recommendation

Compare the monitor region with source-machine locations before diagnosing a missing endpoint as an access failure.

## Article

## Source facts

When creating a connection monitor, the selected region limits the Azure source VMs available. The source picker shows VMs and scale sets bound to that region, grouped by subscription. Connection Monitor also supports on-premises sources with the required monitoring agents.

Destination endpoints can be Azure resources or other URLs and IP addresses. Microsoft distinguishes the current Connection Monitor from the deprecated classic service and documents Azure Monitor Agent support without a legacy Log Analytics agent dependency. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal).

## Applicability

Identify which machine originates each test and which endpoint is the destination. Do not apply a source-region restriction to every destination or mistake an on-premises agent for an Azure VM selection.

## DSE recommendation

DSE recommends preparing the source-to-destination test matrix before creating monitors. Group Azure sources according to their actual regions and verify agent readiness independently. If a source is absent, check region and resource identity before expanding permissions or recreating the VM. Keep the current monitor design separate from obsolete classic-service procedures.

## Verification

In the approved configuration, compare the selected sources with the planned regional inventory and confirm every required test origin is represented. Exercise a harmless connection test to the intended destination and inspect its source identity in the result. A successful test from one region should not close an unconfigured test from another. Record any missing source and its specific prerequisite for follow-up.

## Official references

[Microsoft Learn: Create a Connection Monitor – Azure Portal](https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal). Source retrieved September 9, 2026.

## Primary reference

- Name: Create a Connection Monitor - Azure Portal - Azure Network Watcher | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Match Connection Monitor's region to its Azure source machines,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-380-match-connection-monitor-s-region-to-its-azure-source-machines/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
