Match Connection Monitor's region to its Azure source machines

The region selected for the monitor constrains which Azure VM and scale-set sources appear in its source selection.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

The region selected for the monitor constrains which Azure VM and scale-set sources appear in its source selection.

Potentially affected

Azure Network Watcher Connection Monitor configurations created through the portal.

DSE recommendation

Compare the monitor region with source-machine locations before diagnosing a missing endpoint as an access failure.

Source facts

When creating a connection monitor, the selected region limits the Azure source VMs available. The source picker shows VMs and scale sets bound to that region, grouped by subscription. Connection Monitor also supports on-premises sources with the required monitoring agents.

Destination endpoints can be Azure resources or other URLs and IP addresses. Microsoft distinguishes the current Connection Monitor from the deprecated classic service and documents Azure Monitor Agent support without a legacy Log Analytics agent dependency. Microsoft Learn.

Applicability

Identify which machine originates each test and which endpoint is the destination. Do not apply a source-region restriction to every destination or mistake an on-premises agent for an Azure VM selection.

DSE recommendation

DSE recommends preparing the source-to-destination test matrix before creating monitors. Group Azure sources according to their actual regions and verify agent readiness independently. If a source is absent, check region and resource identity before expanding permissions or recreating the VM. Keep the current monitor design separate from obsolete classic-service procedures.

Verification

In the approved configuration, compare the selected sources with the planned regional inventory and confirm every required test origin is represented. Exercise a harmless connection test to the intended destination and inspect its source identity in the result. A successful test from one region should not close an unconfigured test from another. Record any missing source and its specific prerequisite for follow-up.

Official references

Microsoft Learn: Create a Connection Monitor – Azure Portal. Source retrieved September 9, 2026.

Primary reference

Review the official source

Create a Connection Monitor - Azure Portal - Azure Network Watcher | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE