{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/",
        "slug": "dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/"
        },
        "title": "Recognize tenant-wide targeting before using the Windows client monitoring installer",
        "summary": "Can a monitored-object DCR target only selected Windows clients inside a Microsoft Entra tenant?",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:16+00:00",
        "modified_at": "2026-09-10T00:55:35+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 253,
        "potentially_affected": "Windows 11 clients using Azure Monitor Agent's client installer and preview monitored-object operations.",
        "dse_recommendation": "Treat a monitored-object association as a tenant-wide client-installer decision, not an individual-device assignment.",
        "primary_source": {
            "name": "Set Up the Azure Monitor Agent on Windows Client Devices - Azure Monitor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>With Azure Monitor Agent&#8217;s Windows client installer, a DCR associated with the tenant&#8217;s monitored object applies to all Windows clients running that installer in the tenant. Granular client targeting is unsupported. Agents installed through the VM extension are outside this association&#8217;s scope. Microsoft identifies the monitored-object operations as preview-only. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>The installer uses Microsoft Entra device tokens rather than the VM extension&#8217;s managed identity. Clients must be Entra joined or hybrid joined. This client method does not support private-link monitoring or Azure Monitor Metrics as a destination. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review Windows 11 clients using Azure Monitor Agent&#8217;s client installer and preview monitored-object operations. The method primarily targets continuously connected desktops or workstations; assess laptop limitations and all prerequisites separately.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends listing every client already using this installer before associating a rule with the monitored object. Have the collection owner approve that actual population. Do not describe a resource-group name or a deployment tool&#8217;s pilot group as a DCR targeting boundary that the service does not provide. Keep extension-managed machines in a separate configuration inventory.</p>\n<h2>Verification</h2>\n<p>In an approved test tenant, inspect the monitored object&#8217;s complete association list and compare expected collection on multiple installer-managed clients. Confirm that the resulting destination records identify the intended devices. Review the impact on all existing clients before a production association change; avoid using a tenant-wide change as an unannounced one-device experiment. Preserve the scope decision with the exact rule and association.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Azure Monitor Agent on Windows clients</a>.</p>",
        "content_text": "Source facts\nWith Azure Monitor Agent’s Windows client installer, a DCR associated with the tenant’s monitored object applies to all Windows clients running that installer in the tenant. Granular client targeting is unsupported. Agents installed through the VM extension are outside this association’s scope. Microsoft identifies the monitored-object operations as preview-only. Microsoft Learn.\nThe installer uses Microsoft Entra device tokens rather than the VM extension’s managed identity. Clients must be Entra joined or hybrid joined. This client method does not support private-link monitoring or Azure Monitor Metrics as a destination. Microsoft Learn.\nApplicability\nReview Windows 11 clients using Azure Monitor Agent’s client installer and preview monitored-object operations. The method primarily targets continuously connected desktops or workstations; assess laptop limitations and all prerequisites separately.\nDSE recommendation\nDSE recommends listing every client already using this installer before associating a rule with the monitored object. Have the collection owner approve that actual population. Do not describe a resource-group name or a deployment tool’s pilot group as a DCR targeting boundary that the service does not provide. Keep extension-managed machines in a separate configuration inventory.\nVerification\nIn an approved test tenant, inspect the monitored object’s complete association list and compare expected collection on multiple installer-managed clients. Confirm that the resulting destination records identify the intended devices. Review the impact on all existing clients before a production association change; avoid using a tenant-wide change as an unannounced one-device experiment. Preserve the scope decision with the exact rule and association.\nOfficial references\nMicrosoft Learn: Azure Monitor Agent on Windows clients.",
        "content_markdown": "## Source facts\n\nWith Azure Monitor Agent’s Windows client installer, a DCR associated with the tenant’s monitored object applies to all Windows clients running that installer in the tenant. Granular client targeting is unsupported. Agents installed through the VM extension are outside this association’s scope. Microsoft identifies the monitored-object operations as preview-only. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client).\n\nThe installer uses Microsoft Entra device tokens rather than the VM extension’s managed identity. Clients must be Entra joined or hybrid joined. This client method does not support private-link monitoring or Azure Monitor Metrics as a destination. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client).\n\n## Applicability\n\nReview Windows 11 clients using Azure Monitor Agent’s client installer and preview monitored-object operations. The method primarily targets continuously connected desktops or workstations; assess laptop limitations and all prerequisites separately.\n\n## DSE recommendation\n\nDSE recommends listing every client already using this installer before associating a rule with the monitored object. Have the collection owner approve that actual population. Do not describe a resource-group name or a deployment tool’s pilot group as a DCR targeting boundary that the service does not provide. Keep extension-managed machines in a separate configuration inventory.\n\n## Verification\n\nIn an approved test tenant, inspect the monitored object’s complete association list and compare expected collection on multiple installer-managed clients. Confirm that the resulting destination records identify the intended devices. Review the impact on all existing clients before a production association change; avoid using a tenant-wide change as an unannounced one-device experiment. Preserve the scope decision with the exact rule and association.\n\n## Official references\n\n[Microsoft Learn: Azure Monitor Agent on Windows clients](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Recognize tenant-wide targeting before using the Windows client monitoring installer",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/",
                "headline": "Recognize tenant-wide targeting before using the Windows client monitoring installer",
                "description": "Can a monitored-object DCR target only selected Windows clients inside a Microsoft Entra tenant?",
                "abstract": "Can a monitored-object DCR target only selected Windows clients inside a Microsoft Entra tenant?",
                "articleBody": "Source facts\nWith Azure Monitor Agent’s Windows client installer, a DCR associated with the tenant’s monitored object applies to all Windows clients running that installer in the tenant. Granular client targeting is unsupported. Agents installed through the VM extension are outside this association’s scope. Microsoft identifies the monitored-object operations as preview-only. Microsoft Learn.\nThe installer uses Microsoft Entra device tokens rather than the VM extension’s managed identity. Clients must be Entra joined or hybrid joined. This client method does not support private-link monitoring or Azure Monitor Metrics as a destination. Microsoft Learn.\nApplicability\nReview Windows 11 clients using Azure Monitor Agent’s client installer and preview monitored-object operations. The method primarily targets continuously connected desktops or workstations; assess laptop limitations and all prerequisites separately.\nDSE recommendation\nDSE recommends listing every client already using this installer before associating a rule with the monitored object. Have the collection owner approve that actual population. Do not describe a resource-group name or a deployment tool’s pilot group as a DCR targeting boundary that the service does not provide. Keep extension-managed machines in a separate configuration inventory.\nVerification\nIn an approved test tenant, inspect the monitored object’s complete association list and compare expected collection on multiple installer-managed clients. Confirm that the resulting destination records identify the intended devices. Review the impact on all existing clients before a production association change; avoid using a tenant-wide change as an unannounced one-device experiment. Preserve the scope decision with the exact rule and association.\nOfficial references\nMicrosoft Learn: Azure Monitor Agent on Windows clients.",
                "datePublished": "2026-09-10T00:29:16+00:00",
                "dateModified": "2026-09-10T00:55:35+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Recognize tenant-wide targeting before using the Windows client monitoring installer"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Briefing",
                    "Information priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 253,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Set Up the Azure Monitor Agent on Windows Client Devices - Azure Monitor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client"
                }
            }
        ]
    }
}