Microsoft.Maintenance/maintenanceConfigurations/visibility

LVB 0 Reputation points
2025-03-10T08:34:04.9766667+00:00

Hello,

I'm involved on setting up Microsoft Update Manager in an Enterprise Azure Landing Zone.

I would like to understand the difference between setting the visibility setting in the maintenance Windows for Azure Update Manager from Public to Custom. (Microsoft.Maintenance/maintenanceConfigurations/visibility).

When using the Azure Console, this setting seems to be always set to "Public". I've been told by Microsoft Architects that using Public means that "everyone in the world can see it".

I would like to confirm that this is like this, and in case it's like this, why is this setting used in the UI by default with no option to change unless IaC is used.

My feeling is that in any case, this should be public maybe only the subscription where is setup or in the worst case scenario in the tenant where the subscription belongs to. If this is really published to anyone in the world this would be a major security issue.

Can anyone confirm this?

Thanks in advance

Azure Update Manager
Azure Update Manager
An Azure service to centrally manages updates and compliance at scale.
357 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.