# Do not assume an Azure Monitor Agent proxy setting covers every destination

> Which destination can bypass the configured Azure Monitor Agent proxy?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-518-do-not-assume-an-azure-monitor-agent-proxy-setting-covers-every-destination/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:18+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Which destination can bypass the configured Azure Monitor Agent proxy?

## Potentially affected

Azure Monitor Agent network designs, including the Azure Monitor Metrics preview destination.

## DSE recommendation

Review the actual collection destinations before treating the agent proxy as an exclusive outbound path.

## Article

## Source facts

Azure Monitor Agent supports HTTPS communication through a proxy, including anonymous or basic authentication. However, its Azure Monitor Metrics preview destination does not support that proxy configuration and sends through the public internet. Microsoft also excludes Azure Arc-enabled servers from OMS Gateway connectivity and requires HTTPS inspection to be disabled for the documented agent endpoints. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-network-configuration).

## Applicability

This concerns the agent’s destination-specific network behavior, not a promise that every configured telemetry stream follows one route. The custom-metrics preview is unavailable in Azure Government and Azure operated by 21Vianet. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-network-configuration). Evaluate any preview use under the organization’s existing approval policy.

## DSE recommendation

Review the actual collection destinations before treating the agent proxy as an exclusive outbound path. Separate the log route from any configured custom-metrics route in the network review. Where direct public egress is prohibited, ask the monitoring owner to resolve the incompatible destination choice before deployment. Do not approve a gateway design for Arc solely because an Azure VM example uses one.

## Verification

Inspect the effective agent extension settings and destination configuration on a representative host. Under an approved test, compare the observed connections with the proposed route for each stream and confirm the intended data arrives. Check the inspection policy as well as the proxy setting. Preserve evidence of the actual destination and network path, and raise a specific design exception if either differs from the approved requirement.

## Official references

[Microsoft Learn: Azure Monitor Agent network configuration](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-network-configuration). Source reviewed September 9, 2026.

## Primary reference

- Name: Azure Monitor Agent Network Configuration - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-network-configuration
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not assume an Azure Monitor Agent proxy setting covers every destination,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-518-do-not-assume-an-azure-monitor-agent-proxy-setting-covers-every-destination/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
