Azure VMs with boot diagnostics turned off
What does ZopNight detect here?
ZopNight flags an Azure VM whose `diagnosticsProfile.bootDiagnostics.enabled` setting is false. Without boot diagnostics there is no serial log or boot screenshot to inspect when the VM fails to start, and the Azure Serial Console needs boot diagnostics enabled too. The finding is low severity, covers boot diagnostics only, and claims no saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1305 |
| Category | compliance |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | bootDiagnostics.enabled = false |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read |
Where it applies
Boot diagnostics is how you see a VM that will not boot
Boot diagnostics captures the serial log and a screenshot of the VM’s console while it starts. When a VM hangs on a kernel panic, a failed disk mount or a Windows update loop, those two artefacts are often the only evidence you can get without restoring the disk elsewhere.
It also gates the Azure Serial Console, which requires boot diagnostics to be enabled for the VM. With it off, you lose interactive console access exactly when SSH or RDP is unavailable.
Finding VMs with it switched off
az vm list \ --query "[?diagnosticsProfile.bootDiagnostics.enabled==\`false\`].{name:name, rg:resourceGroup}" \ -o tableTo read the serial log of a VM that has it on, use az vm boot-diagnostics get-boot-log.
The single setting ZopNight reads
The rule reads the VM’s boot diagnostics setting from its Azure definition and fires when it is explicitly false. It is deliberately narrow: guest-level monitoring through the Azure Monitor Agent is not evaluated here, and a VM with full guest telemetry but boot diagnostics off still gets this finding.
VMs with no finding
When the VM’s definition carries no boot diagnostics setting at all, ZopNight treats it as unknown and does not flag it. Tags are not consulted. Microsoft notes that the portal enables boot diagnostics with a managed storage account by default for new VMs, so findings usually point at VMs created from templates or scripts that turned it off.
A troubleshooting gap rated low
There is no saving on this finding, and it is rated low severity. The cost of skipping it shows up during an outage, as extra hours spent recovering a VM that could have been diagnosed from its console log.
Turning boot diagnostics on
- Enable it with a managed storage account, which Azure CLI 2.12.0 and later uses when you pass no storage account:
az vm boot-diagnostics enable --resource-group my-rg --name my-vm- If you must use your own storage account, allow trusted Azure services through its firewall so the platform can publish the screenshot and serial log.
- Grant the operators who need Serial Console the Virtual Machine Contributor role on the VM and on the boot diagnostics storage account.
- Treat guest-level metrics and logs as a separate task; see Azure VM Monitoring Not Enabled.