Skip to main content
compliance · azure

Azure VMs with boot diagnostics turned off

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an Azure VM whose `diagnosticsProfile.bootDiagnostics.enabled` setting is false. Without boot diagnostics there is no serial log or boot screenshot to inspect when the VM fails to start, and the Azure Serial Console needs boot diagnostics enabled too. The finding is low severity, covers boot diagnostics only, and claims no saving.

Signal and threshold

How ZopNight evaluates Azure VMs with boot diagnostics turned off.
Field Value
Rule IDsRC-1305
Categorycompliance
Severitylow
Metricnone — pure configuration read
ThresholdbootDiagnostics.enabled = false
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read

Boot diagnostics is how you see a VM that will not boot

Boot diagnostics captures the serial log and a screenshot of the VM’s console while it starts. When a VM hangs on a kernel panic, a failed disk mount or a Windows update loop, those two artefacts are often the only evidence you can get without restoring the disk elsewhere.

It also gates the Azure Serial Console, which requires boot diagnostics to be enabled for the VM. With it off, you lose interactive console access exactly when SSH or RDP is unavailable.

Finding VMs with it switched off

Terminal window
az vm list \
--query "[?diagnosticsProfile.bootDiagnostics.enabled==\`false\`].{name:name, rg:resourceGroup}" \
-o table

To read the serial log of a VM that has it on, use az vm boot-diagnostics get-boot-log.

The single setting ZopNight reads

The rule reads the VM’s boot diagnostics setting from its Azure definition and fires when it is explicitly false. It is deliberately narrow: guest-level monitoring through the Azure Monitor Agent is not evaluated here, and a VM with full guest telemetry but boot diagnostics off still gets this finding.

VMs with no finding

When the VM’s definition carries no boot diagnostics setting at all, ZopNight treats it as unknown and does not flag it. Tags are not consulted. Microsoft notes that the portal enables boot diagnostics with a managed storage account by default for new VMs, so findings usually point at VMs created from templates or scripts that turned it off.

A troubleshooting gap rated low

There is no saving on this finding, and it is rated low severity. The cost of skipping it shows up during an outage, as extra hours spent recovering a VM that could have been diagnosed from its console log.

Turning boot diagnostics on

  1. Enable it with a managed storage account, which Azure CLI 2.12.0 and later uses when you pass no storage account:
Terminal window
az vm boot-diagnostics enable --resource-group my-rg --name my-vm
  1. If you must use your own storage account, allow trusted Azure services through its firewall so the platform can publish the screenshot and serial log.
  2. Grant the operators who need Serial Console the Virtual Machine Contributor role on the VM and on the boot diagnostics storage account.
  3. Treat guest-level metrics and logs as a separate task; see Azure VM Monitoring Not Enabled.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·