An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
Since the alert fired and the action group shows as triggered, focus on email delivery rather than alert rule evaluation.
Check these items in order:
- In Azure portal, open the fired alert and review the History tab.
- Confirm the email action was not suppressed by an alert processing rule.
- If suppression appears there, adjust or remove the rule.
- Test whether the problem is specific to the team mailbox or distribution list.
- Add a regular work mailbox to the same action group, not just the team email list.
- If the regular mailbox receives the alert but the team address does not, the issue is likely with the team mailbox or mail filtering.
- Verify external sender filtering on the team mailbox or distribution list.
- Azure Monitor recommends allowing these sender addresses in spam filtering and mail security systems:
-
[email protected] -
[email protected] -
******@mail.windowsazure.com
-
- Internal mailing lists and distribution lists commonly block external senders.
- Azure Monitor recommends allowing these sender addresses in spam filtering and mail security systems:
- Check mailbox and mail flow rules.
- Review inbox rules that might delete or move the messages.
- Check spam, quarantine, sender limits, and security appliance filtering in systems such as Exchange or Microsoft 365.
- Reconfirm the recipient did not unsubscribe from the action group.
- Since this was already checked, keep it as a validation point only.
- Use test your action group in the Azure portal again after adding a normal mailbox.
- If test notifications still fail only for the team address, that strongly indicates mail filtering or distribution-list restrictions rather than an Azure Monitor alert-type issue.
- If Azure reports a notification error such as permanent delivery failure or delivery status could not be verified, file a support ticket.
Based on the described behavior, the most likely causes are:
- the team email address is a distribution list or shared mailbox blocking external senders
- spam, quarantine, or transport rules are catching the messages
- an alert processing rule is suppressing that action for some alerts
There is nothing in the provided guidance indicating that one Azure Monitor alert type should be filtered differently at the Azure side when the action group is triggered successfully.