{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/",
        "slug": "dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/"
        },
        "title": "Include other workspace queries in the impact review for one Azure Monitor private-link addition",
        "summary": "Can adding one Log Analytics workspace to AMPLS change the query path for other workspaces?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:16+00:00",
        "modified_at": "2026-09-10T02:11:18+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 244,
        "potentially_affected": "Virtual networks using Azure Monitor Private Link Scope for Log Analytics workspace queries.",
        "dse_recommendation": "Review the full workspace-query population sharing the affected DNS before approving a single workspace's AMPLS addition.",
        "primary_source": {
            "name": "Use Azure Private Link to connect networks to Azure Monitor - Azure Monitor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Log Analytics query endpoints are shared, whereas workspace ingestion endpoints are resource-specific. Adding one workspace to an Azure Monitor Private Link Scope changes the VNet&#8217;s shared query endpoint resolution, so queries to all Log Analytics workspaces from that VNet use the private addresses. Microsoft recommends one AMPLS for networks sharing DNS because multiple scopes can overwrite the Azure Monitor zones. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This is the impact boundary of a Log Analytics query-path change, not a statement that every workspace is automatically authorized. AMPLS Open mode permits resources outside the scope; Private Only restricts access to its private-link resources. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>DSE recommendation</h2>\n<p>Review the full workspace-query population sharing the affected DNS before approving a single workspace&#8217;s AMPLS addition. Include operational tools that query a different workspace than the one named in the change. Decide which of those destinations should remain reachable under the selected query access mode. Keep resource-specific ingestion checks separate so successful uploads do not stand in for a query-impact review.</p>\n<h2>Verification</h2>\n<p>From representative affected clients, test authorized queries to both the newly scoped workspace and other required workspaces. Compare their actual results with the approved access-mode decision and retain the resolved query endpoints. Check that the common DNS design has one intended scope owner. Report only the tested destinations as verified; a successful query to the newly added workspace alone does not close the wider change review.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Azure Monitor private-link structure</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nLog Analytics query endpoints are shared, whereas workspace ingestion endpoints are resource-specific. Adding one workspace to an Azure Monitor Private Link Scope changes the VNet’s shared query endpoint resolution, so queries to all Log Analytics workspaces from that VNet use the private addresses. Microsoft recommends one AMPLS for networks sharing DNS because multiple scopes can overwrite the Azure Monitor zones. Microsoft Learn.\nApplicability\nThis is the impact boundary of a Log Analytics query-path change, not a statement that every workspace is automatically authorized. AMPLS Open mode permits resources outside the scope; Private Only restricts access to its private-link resources. Microsoft Learn.\nDSE recommendation\nReview the full workspace-query population sharing the affected DNS before approving a single workspace’s AMPLS addition. Include operational tools that query a different workspace than the one named in the change. Decide which of those destinations should remain reachable under the selected query access mode. Keep resource-specific ingestion checks separate so successful uploads do not stand in for a query-impact review.\nVerification\nFrom representative affected clients, test authorized queries to both the newly scoped workspace and other required workspaces. Compare their actual results with the approved access-mode decision and retain the resolved query endpoints. Check that the common DNS design has one intended scope owner. Report only the tested destinations as verified; a successful query to the newly added workspace alone does not close the wider change review.\nOfficial references\nMicrosoft Learn: Azure Monitor private-link structure. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nLog Analytics query endpoints are shared, whereas workspace ingestion endpoints are resource-specific. Adding one workspace to an Azure Monitor Private Link Scope changes the VNet’s shared query endpoint resolution, so queries to all Log Analytics workspaces from that VNet use the private addresses. Microsoft recommends one AMPLS for networks sharing DNS because multiple scopes can overwrite the Azure Monitor zones. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security).\n\n## Applicability\n\nThis is the impact boundary of a Log Analytics query-path change, not a statement that every workspace is automatically authorized. AMPLS Open mode permits resources outside the scope; Private Only restricts access to its private-link resources. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security).\n\n## DSE recommendation\n\nReview the full workspace-query population sharing the affected DNS before approving a single workspace’s AMPLS addition. Include operational tools that query a different workspace than the one named in the change. Decide which of those destinations should remain reachable under the selected query access mode. Keep resource-specific ingestion checks separate so successful uploads do not stand in for a query-impact review.\n\n## Verification\n\nFrom representative affected clients, test authorized queries to both the newly scoped workspace and other required workspaces. Compare their actual results with the approved access-mode decision and retain the resolved query endpoints. Check that the common DNS design has one intended scope owner. Report only the tested destinations as verified; a successful query to the newly added workspace alone does not close the wider change review.\n\n## Official references\n\n[Microsoft Learn: Azure Monitor private-link structure](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Include other workspace queries in the impact review for one Azure Monitor private-link addition",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/",
                "headline": "Include other workspace queries in the impact review for one Azure Monitor private-link addition",
                "description": "Can adding one Log Analytics workspace to AMPLS change the query path for other workspaces?",
                "abstract": "Can adding one Log Analytics workspace to AMPLS change the query path for other workspaces?",
                "articleBody": "Source facts\nLog Analytics query endpoints are shared, whereas workspace ingestion endpoints are resource-specific. Adding one workspace to an Azure Monitor Private Link Scope changes the VNet’s shared query endpoint resolution, so queries to all Log Analytics workspaces from that VNet use the private addresses. Microsoft recommends one AMPLS for networks sharing DNS because multiple scopes can overwrite the Azure Monitor zones. Microsoft Learn.\nApplicability\nThis is the impact boundary of a Log Analytics query-path change, not a statement that every workspace is automatically authorized. AMPLS Open mode permits resources outside the scope; Private Only restricts access to its private-link resources. Microsoft Learn.\nDSE recommendation\nReview the full workspace-query population sharing the affected DNS before approving a single workspace’s AMPLS addition. Include operational tools that query a different workspace than the one named in the change. Decide which of those destinations should remain reachable under the selected query access mode. Keep resource-specific ingestion checks separate so successful uploads do not stand in for a query-impact review.\nVerification\nFrom representative affected clients, test authorized queries to both the newly scoped workspace and other required workspaces. Compare their actual results with the approved access-mode decision and retain the resolved query endpoints. Check that the common DNS design has one intended scope owner. Report only the tested destinations as verified; a successful query to the newly added workspace alone does not close the wider change review.\nOfficial references\nMicrosoft Learn: Azure Monitor private-link structure. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:23:16+00:00",
                "dateModified": "2026-09-10T02:11:18+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Include other workspace queries in the impact review for one Azure Monitor private-link addition"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 244,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use Azure Private Link to connect networks to Azure Monitor - Azure Monitor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security"
                }
            }
        ]
    }
}