An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
Azure Monitor Agent on Linux: HTTP 403 through Private Link, no Heartbeat or Syslog
I have Azure Developer Support and need assistance diagnosing persistent Azure Monitor Agent ingestion failures.
Environment:
- Azure commercial, East US.
- Two Ubuntu 24.04 Azure VMs.
- AzureMonitorLinuxAgent extension handler version 1.45.
- System-assigned managed identities.
- A Syslog data collection rule (DCR), data collection endpoint (DCE), and Log Analytics workspace.
- Azure Monitor Private Link Scope (AMPLS) with an approved private endpoint.
- Workspace public ingestion disabled; public queries enabled; local authentication disabled.
- DCE public network access disabled.
- AMPLS ingestion and query access modes set to PrivateOnly.
- AMA extension proxy setting explicitly set to mode "none".
Problem:
Since installation on October 3, 2026, AMA reports HTTP 403 Forbidden uploading both HEALTH_ASSESSMENT_BLOB and LINUX_SYSLOGS_BLOB. No AMA Heartbeat records are returned, and Syslog delivery has not been verified.
Checks already completed:
- Extensions report provisioning Succeeded, and the AMA services are active.
- Both VMs have the intended DCR and DCE associations.
- The agent downloaded the DCR configuration.
- Agent logs show successful managed-identity token retrieval and successful GIG token retrieval for the expected DCR/workspace channel.
- Private DNS and TLS connectivity to DCE endpoints were verified on both VMs.
- On one affected VM, the workspace ODS hostname resolves to the intended private endpoint IP, TLS certificate validation succeeds, and the actual mdsd process has an established connection to that private IP on TCP 443.
- The workspace and DCE are both linked to the intended AMPLS with provisioning Succeeded. The workspace also lists the corresponding private-link association.
- The private endpoint is Approved and targets the correct AMPLS. Its ODS IP configuration lists the expected workspace hostname.
- Workspace data ingestion status is RespectQuota.
- Restarting AMA and generating a fresh authpriv.notice test message did not resolve the issue.
Recent failures occurred on October 4, 2026, at approximately 09:46 UTC. The HTTP 403 responses have an empty response body.
Microsoft's bundled AMA Linux troubleshooter also reported:
file /etc/opt/microsoft/azuremonitoragent/config-cache/fluentbit/td-agent.conf doesn't exist.
We do not know whether that file is relevant to this Syslog-only DCR.
What specific diagnostic should we run next to identify the reason for the 403? If Microsoft needs to trace the failed uploads, please provide an approved private channel for sharing request IDs and resource identifiers. We need to retain private ingestion.
This summary was prepared with AI assistance from observed diagnostic results. Account identifiers, tokens, and research data have been omitted.