# Intersect managed-application region choices with resource-type support

> Review both explicit location choices and the resource types used to filter the portal form.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-427-intersect-managed-application-region-choices-with-resource-type-support/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:49+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Review both explicit location choices and the resource types used to filter the portal form.

## Potentially affected

Azure managed-application createUiDefinition location controls.

## DSE recommendation

DSE recommends tracing each intended region through both filters before broadening the choices.

## Article

## Source facts

In createUiDefinition’s location configuration, allowedValues limits the listed regions while resourceTypes filters for regions supporting those resource types. When both are configured, the displayed choices are their intersection. The resourceTypes filter includes a location only when it supports every listed type. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/create-uidefinition-overview).

## Applicability

Use this distinction when reviewing an unexpectedly short or empty location dropdown for a managed application’s creation experience. Identify the actual allowed-region list and fully qualified resource types in the released definition. Do not diagnose the display from either list in isolation.

## DSE recommendation

DSE recommends tracing each intended region through both filters before broadening the choices. Confirm that the listed resource types describe what the application really deploys, and have the deployment owner review any proposed removal from that list. Treat an empty intersection as a configuration question to resolve rather than hiding the location control or relaxing restrictions without review.

## Verification

Preview the exact interface definition in an approved test experience and compare the displayed locations with the intended intersection. Exercise a case allowed by the explicit list but excluded by resource support, and a supported location omitted from the explicit list. Record both input lists and the observed choices. Keep this UI check separate from the subsequent deployment assessment; a correctly filtered dropdown should not be recorded as a completed resource deployment.

## Official references

[Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/create-uidefinition-overview). Source retrieved September 9, 2026.

## Primary reference

- Name: CreateUiDefinition.json file for portal pane - Azure Managed Applications | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/create-uidefinition-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Intersect managed-application region choices with resource-type support,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-427-intersect-managed-application-region-choices-with-resource-type-support/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
