An Azure service that is used to provision Windows and Linux virtual machines.
Azure VM Run Command and Custom Script Extension Auditability and Governance Concerns
We have been reviewing the security and auditability implications of Azure VM Run Command and VM Extensions and would appreciate guidance from Microsoft and the community regarding governance best practices.
Background
During testing, we observed that Azure VM Run Command executes scripts through the Azure VM Agent rather than through SSH or RDP connectivity. As a result:
- No SSH or RDP access is required.
- No inbound network path to the VM is required.
- The operation is controlled through Azure RBAC permissions.
- The Activity Log records that a Run Command operation occurred and identifies the caller.
- However, the Activity Log does not appear to retain the script contents that were executed.
- Script content and output are only available temporarily on the VM through agent-generated files and may rotate quickly.
According to Microsoft documentation, Azure Activity Log records control-plane operations and retains events for 90 days by default, but we have not found documentation indicating that the executed script body is captured as part of the audit record.
Questions
Is there a Microsoft-recommended way to centrally capture or audit the exact script content executed through:
- Azure VM Run Command
- Custom Script Extension
- Script content - Script hash - Additional execution details within Activity Log, resource logs, or another Azure-native auditing solution?
What is Microsoft's recommended approach to restrict or prevent the use of Run Command in highly regulated environments?
- Azure Policy?
- Custom RBAC roles?
-
allowExtensionOperations=false?- Other recommended controls?
- `Microsoft.Compute/virtualMachines/runCommand/action` - `Microsoft.Compute/virtualMachines/extensions/write` For security and compliance reviews, what is Microsoft's recommended auditing strategy to maintain a long-term record of commands executed through these control-plane mechanisms?
-
- Custom RBAC roles?
Goal
We are trying to understand the Microsoft-recommended governance model for environments where auditability and forensic traceability are required, particularly when privileged code execution can occur through Azure control-plane operations rather than traditional SSH or RDP access paths.
Any official guidance, documentation references, or product recommendations would be appreciated.We have been reviewing the security and auditability implications of Azure VM Run Command and VM Extensions and would appreciate guidance from Microsoft and the community regarding governance best practices.
Background
During testing, we observed that Azure VM Run Command executes scripts through the Azure VM Agent rather than through SSH or RDP connectivity. As a result:
- No SSH or RDP access is required.
- No inbound network path to the VM is required.
- The operation is controlled through Azure RBAC permissions.
- The Activity Log records that a Run Command operation occurred and identifies the caller.
- However, the Activity Log does not appear to retain the script contents that were executed.
- Script content and output are only available temporarily on the VM through agent-generated files and may rotate quickly.
According to Microsoft documentation, Azure Activity Log records control-plane operations and retains events for 90 days by default, but we have not found documentation indicating that the executed script body is captured as part of the audit record. [learn.microsoft.com], [techcommun...rosoft.com]
Questions
Is there a Microsoft-recommended way to centrally capture or audit the exact script content executed through:
- Azure VM Run Command
- Custom Script Extension
- Script content - Script hash - Additional execution details within Activity Log, resource logs, or another Azure-native auditing solution?
What is Microsoft's recommended approach to restrict or prevent the use of Run Command in highly regulated environments?
- Azure Policy?
- Custom RBAC roles?
-
allowExtensionOperations=false?- Other recommended controls?
- `Microsoft.Compute/virtualMachines/runCommand/action` - `Microsoft.Compute/virtualMachines/extensions/write` For security and compliance reviews, what is Microsoft's recommended auditing strategy to maintain a long-term record of commands executed through these control-plane mechanisms?
-
- Custom RBAC roles?
Goal
We are trying to understand the Microsoft-recommended governance model for environments where auditability and forensic traceability are required, particularly when privileged code execution can occur through Azure control-plane operations rather than traditional SSH or RDP access paths.
Any official guidance, documentation references, or product recommendations would be appreciated.