Azure Chaos Studio Workspace Runbook: Safely Simulate Outages and Prove Recovery
Focus keyphrase: Azure Chaos Studio Workspace runbook
If your incident drill currently means “someone says let’s test failover” and everyone goes quiet, this runbook is for you. We’ll set up an Azure Chaos Studio Workspace, run a controlled Scenario in preproduction, and verify recovery with evidence you can reuse for ops reviews and audits.
What this runbook covers
- Workspace scope and identity setup
- Scenario configuration and permission validation
- Execution checks, report review, and rollback hygiene
Numbered flow from admin to workspace creation, managed identity permissions, scenario execution on scoped resources, and scenario report review.
1) Azure admin
Portal + RBAC
2) Chaos Studio Workspace
Scope: RG / Subscription
3) Managed identity
Least-privilege roles
4) Scenario targets in scope
Virtual Machines
Compute Zone Down
NSG / VNet
DNS Outage
Databases
Failover scenarios
5) Scenario report + monitoring
Status, duration, target resources
Prerequisites
| Requirement | Minimum | Why it matters |
|---|---|---|
| Azure access | Contributor on Workspace resource group | Create and configure the Chaos Studio Workspace |
| Role assignment rights | Owner or User Access Administrator on target scope | Grant managed identity access for Scenario actions |
| Subscription setup | Microsoft.Chaos resource provider registered |
Required to deploy Chaos Studio resources |
| Target resources | Preproduction resources in one scoped boundary | Run controlled outage simulations safely |
| Monitoring | Azure Monitor + Log Analytics enabled | Validate recovery, not just fault execution |
Variables
| Placeholder | Description | Example |
|---|---|---|
<SUBSCRIPTION_ID> |
Azure subscription containing the workspace and test resources | 00000000-1111-2222-3333-444444444444 |
<RESOURCE_GROUP> |
Resource group for Chaos Studio workspace | rg-chaos-preprod |
<WORKSPACE_NAME> |
Chaos Studio workspace name | chaos-preprod-westus2 |
<SCOPE_RESOURCE_ID> |
Scoped resource ID (subscription or resource group) | /subscriptions/.../resourceGroups/rg-app-preprod |
<SCENARIO_NAME> |
Scenario to run | Compute Zone Down |
Step-by-step runbook
1) Create the Workspace and set scope
Portal path: Azure portal → Chaos Studio → Workspaces → Create
- Set Subscription, Resource Group, Workspace name, and region.
- On Scope, choose Subscription, Resource group, or Service group for discovery boundary.
- On Identity, select system-assigned or user-assigned managed identity.
Expected result: Workspace is created and starts discovering in-scope resources.
How to verify: Workspace opens successfully and resource inventory begins populating under Scenarios.
2) Grant required roles to the Workspace identity
Portal path: Chaos Studio Workspace → Access banner / Scenario configuration → Fix permissions
Assign only required roles for the planned Scenario actions. Example role mappings from Microsoft Learn include VM Contributor for VM shutdown actions and Network Contributor for NSG-based network outage actions.
# Optional: confirm provider registration
az provider register --namespace Microsoft.Chaos --subscription <SUBSCRIPTION_ID>
# Optional: verify registration state
az provider show --namespace Microsoft.Chaos --subscription <SUBSCRIPTION_ID> --query registrationState -o tsv
Expected result: Validation no longer reports missing permissions for selected scenario actions.
How to verify: Scenario configuration page shows permission checks passing.
3) Configure and run a Scenario in preproduction
Portal path: Chaos Studio Workspace → Scenarios → <SCENARIO_NAME> → Save configuration → Run
- Choose a Scenario (for example, Compute Zone Down or DNS Outage).
- Set required parameters (for example zone filters) and optionally exclude sensitive resources.
- Run the Scenario and monitor action state.
Expected result: Run completes with action-level status and duration captured in a Scenario report.
How to verify: Workspace → Reports shows run status, targeted resources, action timeline, and execution flow.
Five-step sequence: choose scenario, validate permissions, run scenario, review action status, and validate application recovery evidence.
1) Select
Scenario
2) Validate
Permissions
3) Run
Scenario
4) Review
Action status
5) Confirm
Recovery
Checks to complete before you call this a successful drill
• Scenario status = Succeeded (or expected partial outcomes documented)
• Expected resources were actually targeted (not silently skipped)
• App metrics/logs show recovery within target RTO
Verification checklist
- Workspace scope includes exactly intended preproduction resources.
- Managed identity has required roles and no broad unnecessary roles.
- Scenario run has a report with action statuses, durations, and targeted resources.
- Skipped actions were reviewed and understood.
- Application telemetry confirms recovery behavior after injected faults.
Rollback and recovery steps
- Cancel any active Scenario run from the Scenario run view if outcomes are outside expected blast radius.
- Validate temporary disruption actions are removed (for example NSG deny rules from outage simulation).
- If a service remains degraded, run standard workload rollback (deployment rollback, failover reversal, or traffic failback) per app runbook.
- Capture Scenario report and monitoring evidence for postmortem.
Common errors and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| Scenario validation fails with missing permission | Workspace identity lacks required RBAC role | Use Fix Permissions or assign least-privilege custom role manually |
| Run succeeds but expected resource not affected | Resource outside scope or excluded by filter | Review Workspace scope and Scenario filters, then rerun in preprod |
| Too many skipped actions | Scenario template targets resources not present in scope | Confirm intended target types exist; adjust Scenario choice |
| Report looks clean but app still failed | Fault execution succeeded, app resiliency did not | Correlate report with Azure Monitor metrics/logs and update app recovery controls |
Topic selection and exclusion evidence: output/spmonkey-azure-chaos-studio-workspace-runbook-2026-10-09-topic-selection.json
Sources
- Microsoft Learn: What is Azure Chaos Studio?
- Microsoft Learn: Quickstart — Create a Workspace and run a Scenario
- Microsoft Learn: Permissions and identity in Chaos Studio Workspaces
- Microsoft Learn: Scenarios and outage templates for Chaos Studio Workspaces
- Microsoft Learn: Scenario reports in Chaos Studio Workspaces
Discover more from SharePoint Monkey
Subscribe to get the latest posts sent to your email.