All articles
Azure AI09 Aug 2026 · 2 min read

Getting Started With Azure Monitor Alerts

Setting up your first alert before something breaks, not after

By Shehryar Hassan, Microsoft 365 & Azure Consultant

If you've ever found out about a problem because a user called you, instead of because Azure told you first, you're not using Azure Monitor alerts yet. That's normal. A lot of small Azure setups run for months without a single alert rule, and everything looks fine until a VM runs out of disk space at 2am and nobody knows until 9am.

An alert rule in Azure Monitor has three parts: a signal, a condition, and an action. The signal is a metric or a log, like CPU percentage, disk space, or a failed login count. The condition is the threshold, for example "over 90 percent for 5 minutes." The action is what happens when that condition is met, usually an email or a text through an action group.

Setting up your first alert

Start with something you actually care about, not everything at once. A good first alert is disk space on a VM that hosts something important, or failed sign-ins if you're watching security. In the portal, go to Monitor, then Alerts, then Create alert rule. Pick your resource, pick the signal (Azure gives you a list based on what that resource can report), set your condition, and attach or create an action group.

An action group is just a reusable list of who gets notified and how. You can point it at email, SMS, a phone call, or even a webhook if you want it to trigger something else. Build one action group for your team and reuse it across alerts instead of typing your email in every time.

What trips people up

The biggest mistake I see is setting the threshold too tight, so you get paged for things that don't matter and start ignoring alerts entirely. Start loose. If you're watching CPU, don't alert at 70 percent, alert at 90 percent sustained for 10 or 15 minutes. You can always tighten it later once you know what normal looks like for that resource.

The second mistake is forgetting alerts cost money at scale, especially log based ones querying large data volumes. For a handful of VMs this won't matter, but check your pricing tier if you're watching dozens of resources.

Start with two or three alerts on the things that would actually hurt if they broke. That's worth more than a dashboard full of metrics nobody watches.

#Azure#Azure Monitor

Get new posts by email

One note when there is something worth reading. No spam, unsubscribe anytime.

By subscribing you agree to the privacy policy.