Choose ACI diagnostic settings when the workspace cannot accept legacy key-based logging

Legacy Container Instances logging requires public workspace access and local authentication; diagnostic settings use a different supported path.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Legacy Container Instances logging requires public workspace access and local authentication; diagnostic settings use a different supported path.

Potentially affected

Azure Container Instances log collection into Log Analytics workspaces.

DSE recommendation

Identify the integration before changing workspace access, and validate the replacement tables and queries.

Source facts

The legacy Container Instances integration requires a workspace key, publicly accessible Log Analytics workspace and enabled local authentication. It does not support private endpoints.

Microsoft documents diagnostic settings as an alternative that supports private-endpoint workspaces and does not require a workspace key because Resource Manager handles authentication. It sends logs to standard Azure Monitor tables instead of the legacy custom tables. Microsoft Learn.

Applicability

Identify how each container group currently sends logs and which tables its queries and alerts use. Do not infer the collection path solely from the presence of a workspace destination.

DSE recommendation

DSE recommends choosing a supported collection path before restricting workspace access or disabling local authentication. Review the expected destination tables with the monitoring owner and update dependent queries as part of the same controlled change. Avoid reopening public access merely to preserve an unidentified legacy configuration. Keep workspace keys out of diagnostic tickets and migration evidence.

Verification

Emit an approved harmless log message and container event through the intended configuration. Confirm they appear in the expected tables and that the revised queries find them. Verify the desired workspace access settings separately. Retain the group identity, integration choice and observed records so a successful deployment setting is not mistaken for proof that alerting still consumes the correct data.

Official references

Microsoft Learn: Collect & analyze resource logs. Source retrieved September 9, 2026.

Primary reference

Review the official source

Collect & analyze resource logs - Azure Container Instances | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE