{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/",
        "slug": "dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/"
        },
        "title": "Backfill each member policy when deploying a diagnostic-settings initiative",
        "summary": "Does assigning a diagnostic-settings initiative automatically configure every existing resource?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:10+00:00",
        "modified_at": "2026-09-10T00:55:35+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 230,
        "potentially_affected": "Supported Azure resources receiving diagnostic settings through built-in logging policies or initiatives.",
        "dse_recommendation": "Track remediation for every applicable member policy and compare existing-resource coverage with the new-resource path.",
        "primary_source": {
            "name": "Enable Diagnostic Settings by Category Group Using Built-in Policies - Azure Monitor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/platform/diagnostic-settings-policy-built-in",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For the documented diagnostic-settings deployment, assignment without remediation applies to resources created afterward, not the existing population. Existing resources require a remediation task. An initiative requires a task for each constituent policy, and the task identifies that member through its definition-reference ID. Microsoft provides a Remediation tasks view for tracking the resulting work. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/platform/diagnostic-settings-policy-built-in\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this backfill check for built-in diagnostic-setting initiatives covering supported resource types. Separate assignment creation, member-policy remediation and the actual arrival of expected logs; each is a different acceptance question.</p>\n<h2>DSE recommendation</h2>\n<p>Track remediation for every applicable member policy and compare existing-resource coverage with the new-resource path. Build the expected list from the initiative&#8217;s definitions and the resource inventory, rather than assuming that one completed task represents the whole initiative. Have the monitoring owner review the destination and intended categories before backfilling existing resources. Preserve unresolved member policies as visible rollout work.</p>\n<h2>Verification</h2>\n<p>Compare task records and definition-reference IDs with the expected member list. Inspect representative existing resources of each applicable type for the intended diagnostic setting, then verify that an approved test event reaches the selected destination. Check a newly created test resource separately. Do not report full historical-population coverage from a successful initiative assignment or a single resource&#8217;s logs; document remaining gaps by resource type and owning task.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/platform/diagnostic-settings-policy-built-in\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Built-in policies for diagnostic settings</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nFor the documented diagnostic-settings deployment, assignment without remediation applies to resources created afterward, not the existing population. Existing resources require a remediation task. An initiative requires a task for each constituent policy, and the task identifies that member through its definition-reference ID. Microsoft provides a Remediation tasks view for tracking the resulting work. Microsoft Learn.\nApplicability\nUse this backfill check for built-in diagnostic-setting initiatives covering supported resource types. Separate assignment creation, member-policy remediation and the actual arrival of expected logs; each is a different acceptance question.\nDSE recommendation\nTrack remediation for every applicable member policy and compare existing-resource coverage with the new-resource path. Build the expected list from the initiative’s definitions and the resource inventory, rather than assuming that one completed task represents the whole initiative. Have the monitoring owner review the destination and intended categories before backfilling existing resources. Preserve unresolved member policies as visible rollout work.\nVerification\nCompare task records and definition-reference IDs with the expected member list. Inspect representative existing resources of each applicable type for the intended diagnostic setting, then verify that an approved test event reaches the selected destination. Check a newly created test resource separately. Do not report full historical-population coverage from a successful initiative assignment or a single resource’s logs; document remaining gaps by resource type and owning task.\nOfficial references\nMicrosoft Learn: Built-in policies for diagnostic settings. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nFor the documented diagnostic-settings deployment, assignment without remediation applies to resources created afterward, not the existing population. Existing resources require a remediation task. An initiative requires a task for each constituent policy, and the task identifies that member through its definition-reference ID. Microsoft provides a Remediation tasks view for tracking the resulting work. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/diagnostic-settings-policy-built-in).\n\n## Applicability\n\nUse this backfill check for built-in diagnostic-setting initiatives covering supported resource types. Separate assignment creation, member-policy remediation and the actual arrival of expected logs; each is a different acceptance question.\n\n## DSE recommendation\n\nTrack remediation for every applicable member policy and compare existing-resource coverage with the new-resource path. Build the expected list from the initiative’s definitions and the resource inventory, rather than assuming that one completed task represents the whole initiative. Have the monitoring owner review the destination and intended categories before backfilling existing resources. Preserve unresolved member policies as visible rollout work.\n\n## Verification\n\nCompare task records and definition-reference IDs with the expected member list. Inspect representative existing resources of each applicable type for the intended diagnostic setting, then verify that an approved test event reaches the selected destination. Check a newly created test resource separately. Do not report full historical-population coverage from a successful initiative assignment or a single resource’s logs; document remaining gaps by resource type and owning task.\n\n## Official references\n\n[Microsoft Learn: Built-in policies for diagnostic settings](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/diagnostic-settings-policy-built-in). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Backfill each member policy when deploying a diagnostic-settings initiative",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/",
                "headline": "Backfill each member policy when deploying a diagnostic-settings initiative",
                "description": "Does assigning a diagnostic-settings initiative automatically configure every existing resource?",
                "abstract": "Does assigning a diagnostic-settings initiative automatically configure every existing resource?",
                "articleBody": "Source facts\nFor the documented diagnostic-settings deployment, assignment without remediation applies to resources created afterward, not the existing population. Existing resources require a remediation task. An initiative requires a task for each constituent policy, and the task identifies that member through its definition-reference ID. Microsoft provides a Remediation tasks view for tracking the resulting work. Microsoft Learn.\nApplicability\nUse this backfill check for built-in diagnostic-setting initiatives covering supported resource types. Separate assignment creation, member-policy remediation and the actual arrival of expected logs; each is a different acceptance question.\nDSE recommendation\nTrack remediation for every applicable member policy and compare existing-resource coverage with the new-resource path. Build the expected list from the initiative’s definitions and the resource inventory, rather than assuming that one completed task represents the whole initiative. Have the monitoring owner review the destination and intended categories before backfilling existing resources. Preserve unresolved member policies as visible rollout work.\nVerification\nCompare task records and definition-reference IDs with the expected member list. Inspect representative existing resources of each applicable type for the intended diagnostic setting, then verify that an approved test event reaches the selected destination. Check a newly created test resource separately. Do not report full historical-population coverage from a successful initiative assignment or a single resource’s logs; document remaining gaps by resource type and owning task.\nOfficial references\nMicrosoft Learn: Built-in policies for diagnostic settings. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:29:10+00:00",
                "dateModified": "2026-09-10T00:55:35+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Backfill each member policy when deploying a diagnostic-settings initiative"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 230,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Enable Diagnostic Settings by Category Group Using Built-in Policies - Azure Monitor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/platform/diagnostic-settings-policy-built-in"
                }
            }
        ]
    }
}