# Choose ACI diagnostic settings when the workspace cannot accept legacy key-based logging

> Legacy Container Instances logging requires public workspace access and local authentication; diagnostic settings use a different supported path.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-403-choose-aci-diagnostic-settings-when-the-workspace-cannot-accept-legacy-key-based/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:13+00:00
- Modified: 2026-09-10T02:04:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Legacy Container Instances logging requires public workspace access and local authentication; diagnostic settings use a different supported path.

## Potentially affected

Azure Container Instances log collection into Log Analytics workspaces.

## DSE recommendation

Identify the integration before changing workspace access, and validate the replacement tables and queries.

## Article

## Source facts

The legacy Container Instances integration requires a workspace key, publicly accessible Log Analytics workspace and enabled local authentication. It does not support private endpoints.

Microsoft documents diagnostic settings as an alternative that supports private-endpoint workspaces and does not require a workspace key because Resource Manager handles authentication. It sends logs to standard Azure Monitor tables instead of the legacy custom tables. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/container-instances/container-instances-log-analytics).

## Applicability

Identify how each container group currently sends logs and which tables its queries and alerts use. Do not infer the collection path solely from the presence of a workspace destination.

## DSE recommendation

DSE recommends choosing a supported collection path before restricting workspace access or disabling local authentication. Review the expected destination tables with the monitoring owner and update dependent queries as part of the same controlled change. Avoid reopening public access merely to preserve an unidentified legacy configuration. Keep workspace keys out of diagnostic tickets and migration evidence.

## Verification

Emit an approved harmless log message and container event through the intended configuration. Confirm they appear in the expected tables and that the revised queries find them. Verify the desired workspace access settings separately. Retain the group identity, integration choice and observed records so a successful deployment setting is not mistaken for proof that alerting still consumes the correct data.

## Official references

[Microsoft Learn: Collect & analyze resource logs](https://learn.microsoft.com/en-us/azure/container-instances/container-instances-log-analytics). Source retrieved September 9, 2026.

## Primary reference

- Name: Collect & analyze resource logs - Azure Container Instances | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/container-instances/container-instances-log-analytics
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose ACI diagnostic settings when the workspace cannot accept legacy key-based logging,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-403-choose-aci-diagnostic-settings-when-the-workspace-cannot-accept-legacy-key-based/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
