You have an Azure virtual machine named VM1 that runs Windows Server.
You need to perform the following tasks on VM1:
Configure Windows Defender Firewall to allow Remote Desktop connections.
Configure where to store the logs of the virtual machine console.
Which two settings should you use?
Serial console (under Support + troubleshooting on the VM blade) opens a text-based connection to the VM's COM1 serial port that works independently of the network and of the guest operating system's state. After connecting you get the SAC> prompt, enter cmd to create a channel, sign in with administrative credentials, and can then run netsh advfirewall firewall set rule dir=in name="Remote Desktop - User Mode (TCP-In)" new enable=yes (or Enable-NetFirewallRule in PowerShell) to open the Windows Defender Firewall rule for Remote Desktop. Microsoft lists exactly this in the serial console's common-scenarios table: 'Incorrect firewall rules -> Access Serial Console and fix Windows Firewall rules.' It is the right tool here precisely because RDP is what is broken, so you cannot use RDP to fix it. Boot diagnostics is the feature that captures the virtual machine's console output: it collects serial log information and a screenshot of the VM as it boots, and its Settings page is where you choose whether that data lands in a Microsoft-managed storage account or in a custom storage account you nominate. That storage-account choice is precisely 'where to store the logs of the virtual machine console', and it is also where serial console session output is retained. Diagnostic settings is the wrong pick for that task: an Azure Monitor diagnostic setting only routes platform metrics, the activity log and resource logs to a Log Analytics workspace, storage account, event hub or partner solution, and it exposes no VM serial or console log category at all. Metrics, Logs and Workbooks are Azure Monitor views rather than configuration for console log storage; Performance diagnostics, Resource health, Connection troubleshoot, Connection monitor (classic), Reset password and Redeploy + reapply address other troubleshooting problems and neither open a guest firewall rule nor set a log destination.
Community Discussion