{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/",
        "slug": "dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/"
        },
        "title": "Distinguish a Policy reevaluation from a fresh guest configuration audit",
        "summary": "An on-demand Azure Policy evaluation reads the latest Machine Configuration result; it does not initiate another check inside the machine.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:27:11+00:00",
        "modified_at": "2026-09-10T01:23:49+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 235,
        "potentially_affected": "Azure Policy evaluations of Machine Configuration results for Azure and Arc-enabled machines.",
        "dse_recommendation": "Verify the underlying guest audit's freshness before using a reevaluated policy result to close a configuration change.",
        "primary_source": {
            "name": "Azure Machine Configuration prerequisites - Azure Machine Configuration | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/02-setup-prerequisites",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>An on-demand Azure Policy evaluation retrieves the latest result held by the Machine Configuration resource provider. It does not trigger a new operation inside the machine; the resulting policy status is written to Azure Resource Graph.</p>\n<p>The agent checks for assignment changes every five minutes and normally rechecks an assigned configuration every fifteen minutes. Multiple configurations run sequentially, so a long-running one can delay the others. <a href=\"https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/02-setup-prerequisites\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the guest assignment, machine and configuration change being assessed. Keep the time of policy reevaluation separate from the time represented by the guest&#8217;s result.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends a closure record that identifies the underlying audit and its relationship to the change window. If the latest result predates the change, leave the verification pending and investigate the guest audit&#8217;s progress. Do not repeatedly request policy evaluation as a substitute for confirming that the in-machine work completed. Review a slow configuration&#8217;s effect on the other assigned checks before treating a delayed result as a policy-engine failure.</p>\n<h2>Verification</h2>\n<p>After an approved test change, observe the guest audit and the subsequent reported policy state. Retain the assignment identity and available timing evidence for both stages. Confirm that the result used for closure reflects the intended configuration. Record any missing or ambiguous timing rather than describing a refreshed portal view as a newly executed guest test.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/02-setup-prerequisites\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Azure Machine Configuration prerequisites</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nAn on-demand Azure Policy evaluation retrieves the latest result held by the Machine Configuration resource provider. It does not trigger a new operation inside the machine; the resulting policy status is written to Azure Resource Graph.\nThe agent checks for assignment changes every five minutes and normally rechecks an assigned configuration every fifteen minutes. Multiple configurations run sequentially, so a long-running one can delay the others. Microsoft Learn.\nApplicability\nIdentify the guest assignment, machine and configuration change being assessed. Keep the time of policy reevaluation separate from the time represented by the guest’s result.\nDSE recommendation\nDSE recommends a closure record that identifies the underlying audit and its relationship to the change window. If the latest result predates the change, leave the verification pending and investigate the guest audit’s progress. Do not repeatedly request policy evaluation as a substitute for confirming that the in-machine work completed. Review a slow configuration’s effect on the other assigned checks before treating a delayed result as a policy-engine failure.\nVerification\nAfter an approved test change, observe the guest audit and the subsequent reported policy state. Retain the assignment identity and available timing evidence for both stages. Confirm that the result used for closure reflects the intended configuration. Record any missing or ambiguous timing rather than describing a refreshed portal view as a newly executed guest test.\nOfficial references\nMicrosoft Learn: Azure Machine Configuration prerequisites. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nAn on-demand Azure Policy evaluation retrieves the latest result held by the Machine Configuration resource provider. It does not trigger a new operation inside the machine; the resulting policy status is written to Azure Resource Graph.\n\nThe agent checks for assignment changes every five minutes and normally rechecks an assigned configuration every fifteen minutes. Multiple configurations run sequentially, so a long-running one can delay the others. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/02-setup-prerequisites).\n\n## Applicability\n\nIdentify the guest assignment, machine and configuration change being assessed. Keep the time of policy reevaluation separate from the time represented by the guest’s result.\n\n## DSE recommendation\n\nDSE recommends a closure record that identifies the underlying audit and its relationship to the change window. If the latest result predates the change, leave the verification pending and investigate the guest audit’s progress. Do not repeatedly request policy evaluation as a substitute for confirming that the in-machine work completed. Review a slow configuration’s effect on the other assigned checks before treating a delayed result as a policy-engine failure.\n\n## Verification\n\nAfter an approved test change, observe the guest audit and the subsequent reported policy state. Retain the assignment identity and available timing evidence for both stages. Confirm that the result used for closure reflects the intended configuration. Record any missing or ambiguous timing rather than describing a refreshed portal view as a newly executed guest test.\n\n## Official references\n\n[Microsoft Learn: Azure Machine Configuration prerequisites](https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/02-setup-prerequisites). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Distinguish a Policy reevaluation from a fresh guest configuration audit",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/",
                "headline": "Distinguish a Policy reevaluation from a fresh guest configuration audit",
                "description": "An on-demand Azure Policy evaluation reads the latest Machine Configuration result; it does not initiate another check inside the machine.",
                "abstract": "An on-demand Azure Policy evaluation reads the latest Machine Configuration result; it does not initiate another check inside the machine.",
                "articleBody": "Source facts\nAn on-demand Azure Policy evaluation retrieves the latest result held by the Machine Configuration resource provider. It does not trigger a new operation inside the machine; the resulting policy status is written to Azure Resource Graph.\nThe agent checks for assignment changes every five minutes and normally rechecks an assigned configuration every fifteen minutes. Multiple configurations run sequentially, so a long-running one can delay the others. Microsoft Learn.\nApplicability\nIdentify the guest assignment, machine and configuration change being assessed. Keep the time of policy reevaluation separate from the time represented by the guest’s result.\nDSE recommendation\nDSE recommends a closure record that identifies the underlying audit and its relationship to the change window. If the latest result predates the change, leave the verification pending and investigate the guest audit’s progress. Do not repeatedly request policy evaluation as a substitute for confirming that the in-machine work completed. Review a slow configuration’s effect on the other assigned checks before treating a delayed result as a policy-engine failure.\nVerification\nAfter an approved test change, observe the guest audit and the subsequent reported policy state. Retain the assignment identity and available timing evidence for both stages. Confirm that the result used for closure reflects the intended configuration. Record any missing or ambiguous timing rather than describing a refreshed portal view as a newly executed guest test.\nOfficial references\nMicrosoft Learn: Azure Machine Configuration prerequisites. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:27:11+00:00",
                "dateModified": "2026-09-10T01:23:49+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Distinguish a Policy reevaluation from a fresh guest configuration audit"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 235,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Azure Machine Configuration prerequisites - Azure Machine Configuration | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/02-setup-prerequisites"
                }
            }
        ]
    }
}