Resource groups with overlapping IP addresses should use different vIPS clusters.
Though the same policy group can be applied to all the VM groups, VM groups cannot span across multiple resource groups.
The name of the attacker VM will be derived by querying your Azure subscription account for the attacker's IP address. If the attacker is external and has an IP address that matches any of the virtual machines in the Azure subscription account, the virtual machine with the matching IP address will be identified as the attacker.
Trellix recommends deploying the Virtual IPS Sensor and the protected groups in the same region.
Usage guidelines
- Published on Oct 5, 2026
- 1 minute(s) read
Was this article helpful?