# Do not treat a successful Azure Firewall packet capture as coverage of every instance

> The documented success threshold is captures from at least half of the firewall's underlying compute instances.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:20+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

The documented success threshold is captures from at least half of the firewall's underlying compute instances.

## Potentially affected

Azure Firewall packet-capture investigations with the required Management NIC enabled.

## DSE recommendation

Record capture coverage limits, filters and stop conditions before drawing a negative traffic conclusion.

## Article

## Source facts

Azure reports packet-capture success when at least half of the firewall’s underlying compute instances provide captures. The portal does not identify which instances contributed. Success therefore does not establish complete instance coverage.

A capture requires at least one filter and records matching traffic in both directions. Both a packet maximum and a time limit are required; whichever is reached first stops collection. The documented feature also requires an enabled Management NIC. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/firewall/packet-capture).

## Applicability

Review the actual capture prerequisites, approved storage destination, filters and diagnostic objective before collection. Keep capture-data access and retention under the organization’s security controls; this article is not a blanket approval for the storage settings in a tutorial.

## DSE recommendation

DSE recommends preserving the success status together with its documented coverage limit. Describe a missing packet as absent from the collected evidence, not proof that no firewall instance processed it. Review whether filters and stop conditions were capable of observing the traffic in question before planning further collection. Broaden collection only with appropriate approval for the additional data.

## Verification

Use a controlled test flow to check the intended capture filter and inspect the resulting files and timing. Compare the observed traffic with the selected protocol and stop limits. Record any unknown instance coverage explicitly and corroborate the investigation through other approved evidence where needed. Do not silently upgrade a successful collection status into a complete traffic history.

## Official references

[Microsoft Learn: Use Packet Capture to Troubleshoot Azure Firewall](https://learn.microsoft.com/en-us/azure/firewall/packet-capture). Source retrieved September 9, 2026.

## Primary reference

- Name: Use Packet Capture to Troubleshoot Azure Firewall | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/firewall/packet-capture
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not treat a successful Azure Firewall packet capture as coverage of every instance,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-576-do-not-treat-a-successful-azure-firewall-packet-capture-as-coverage-of-every/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
