Loading...

Monitor mode: Azure’s monitoring capabilities delivered securely to Azure Arc-enabled servers

Monitor mode: Azure’s monitoring capabilities delivered securely to Azure Arc-enabled servers

Monitor mode offers a simple and scalable way for customers to configure the Connected Machine agent for monitoring and security scenarios across hybrid, multicloud, and edge environments. 

 

aurnovcy_0-1654639295100.png

 

Security controls provide flexibility and customization in locking down the Connected Machine agent.

 

While Azure Arc-enabled servers affords a robust range of capabilities delivered through extensions and Machine Configuration, some of these capabilities may not be appropriate for sensitive servers like Active Directory Domain controllers or severs handling sensitive payment data. Available from Connected Machine agent 1.16 and above, security controls provide users the flexibility to lock down the Connected Machine agent’s capabilities.  For example, if you want to avoid usage of Custom Script Extension on Azure Arc-enabled servers, security controls could be used to define an allow list of extensions or block list of extensions. Alternatively, if you want to avoid configuring server settings with Machine Configuration, the Guest Configuration service can be disabled with a security control. Security controls provide flexibility to lock down the Connected Machine agent on your terms.

 

Monitor mode groups together a set of predefined security controls, appropriate for using Azure Arc-enabled servers in restricted monitoring and security scenarios.

 

Modes are pre-defined configurations of security controls, extension allow lists and guest configuration, maintained by Microsoft. Available from Connected Machine agent 1.18 and above, Monitor mode groups together the appropriate security controls to limit Connected Machine Agent capabilities to only monitoring and security scenarios. Monitor mode has disabled Machine Configuration capabilities and allows only a limited set of extensions for monitoring and security. Moreover, Monitor mode disables the configuration property for incoming connection ports, preventing capabilities like SSH Arc and Windows Admin Center (WAC), which can be used for remote management of Azure Arc-enabled servers. Note, as more monitoring and security extensions are made available, Microsoft will update the allow list and agent configuration. This list of extensions cannot be modified from Monitor Mode. To define a custom list of allowed extensions, full mode with security controls must be used. With Monitor mode, Azure Arc-enabled servers will extend OS support to Windows 10 customers for their migration from legacy Log Analytics agents (both MMA on Windows and OMS on Linux) to Azure Monitor agent (AMA). Monitor mode provides a built-in offering a streamlined approach to locking down the Connected Machine agent.

 

A subset of Connected Machine agent capabilities (Full mode) are available in Monitor mode. 

 

Capability

Full mode (Default)

Monitor mode

Microsoft Defender for Cloud

Allowed

Allowed

Microsoft Sentinel

Allowed

Allowed

Azure Monitor agent

Allowed

 

Log Analytics extension

Allowed

Allowed

VM Insights (Service Map)

Allowed

Allowed

Qualys

Allowed

Allowed

Custom Script Extension

Allowed

Not Allowed

Azure Automation Update Management (v1)

Allowed

Allowed

Update Management Center (v2)

Allowed

Not Allowed

Hybrid Runbook Worker

Allowed

Not Allowed

Change Tracking & Inventory Management

Allowed

Not Allowed

Key Vault

Allowed

Not Allowed

Machine Configuration (Guest Configuration)

Enabled

Disabled

Connectivity to Windows Admin Center and SSH Arc

Enabled

Disabled

 

As customers continue to leverage Azure Arc-enabled servers for extending their Azure’s observability services to their non-Azure infrastructure, Monitor mode empowers users with the control to meet the diverse security needs of their heterogeneous compute.

 

Published on:

Learn more
Azure Arc Blog articles
Azure Arc Blog articles

Azure Arc Blog articles

Share post:

Related posts

Azure Adaptive Cloud Pre-Days at Microsoft Ignite 2024

As the excitement builds for Microsoft Ignite 2024, tech enthusiasts and professionals worldwide are eagerly anticipating the Azure Adaptive C...

1 year ago

Launching the Arc Jumpstart Newsletter: October 2024 Edition

👋 Welcome! We are excited to kick off this monthly newsletter, where you can get the latest updates on everything happening in the Arc Jumpst...

1 year ago

Announcing Public Preview of Windows Server Hotpatch enabled by Azure Arc

We’re excited to announce the Public Preview of Hotpatch enabled by Azure Arc for Windows Sever 2025 Datacenter and Standard editions!   ...

1 year ago

Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes

Release Summary  We are thrilled to announce the Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes, a groundbre...

1 year ago

Introducing ArcBox 3.0 General Availability

Today, the Arc Jumpstart team is excited to announce the general availability of ArcBox 3.0!   Since it was first introduced in 2021, Ar...

2 years ago

CloudCasa for Azure Arc

Azure Arc is a platform that helps users build and develop their applications by extending Azure to their datacenters, edge, or even to multic...

2 years ago

Generally Available: Transition to WS2012 / R2 ESUs enabled by Azure Arc from Volume Licensing

Customers that have enrolled in WS2012/ R2 ESUs through Volume Licensing for Year 1 can transition to Azure Arc for Year 2 of the program. Ext...

2 years ago

Comparing feature sets for AKS enabled by Azure Arc deployment options

This article shows a comparison of features available for the different deployment options under AKS enabled by Azure Arc.    ...

2 years ago

Increasing Security for SQL Server Enabled by Azure Arc

Back in November 2023, the least privileges deployment model was introduced as a public preview. After thorough testing, we are excited to ann...

2 years ago

Five Key Updates on WS2012 ESUs enabled by Azure Arc

We have a myriad of key updates for customers enrolled in WS2012/R2 ESUs enabled by Azure Arc! As we continue to refine and expand the offer, ...

2 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.