# Read VM Application audit compliance within its operating-system filter

> Does the supplied VM Application policy's compliant result prove the application exists on every resource?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-100-read-vm-application-audit-compliance-within-its-operating-system-filter/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:16+00:00
- Modified: 2026-09-10T00:35:08+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does the supplied VM Application policy's compliant result prove the application exists on every resource?

## Potentially affected

Teams adapting Microsoft's sample Azure Policy audit for required VM Applications across Windows and Linux resources.

## DSE recommendation

Report the intended operating-system cohort separately from resources that fall outside the application's platform filter.

## Article

## Source facts

Microsoft’s VM Application audit sample checks application-profile references with an operating-system condition. The guide explicitly treats a Linux application checked against Windows, or a Windows application against Linux, as compliant. In the matching population, missing applicationProfile data also counts as noncompliant. Audit reports presence; the separate modify design injects application references, and existing resources need remediation tasks. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/vm-applications-inject-with-policy).

## Applicability

Review the actual policy definition, assignment scope, application name, and osType parameter before presenting a rollout percentage. This article describes the supplied sample, not every custom policy. Identify the version and regional replication requirements separately from the sample’s presence check.

## DSE recommendation

Report the intended operating-system cohort separately from resources that fall outside the application’s platform filter. Have the application owner agree which resources truly require the package. Preserve the distinction between observing absence and authorizing a change to existing machines. When remediation is approved, scope it gradually and include the assignment identity and required gallery access in the readiness review.

## Verification

Evaluate representative matching and nonmatching operating systems, including a matching VM without an applicationProfile. Compare the policy outcome with the conditions in the definition rather than interpreting every compliant resource as an installed application. Verify a remediated target’s actual application state independently. Retain the policy version, parameters, target cohort, and observed results so a later platform-filter change does not silently alter the meaning of the score.

## Official references

[Microsoft Learn: Govern VM Applications with Azure Policy](https://learn.microsoft.com/en-us/azure/virtual-machines/vm-applications-inject-with-policy). Source reviewed September 9, 2026.

## Primary reference

- Name: Govern and enforce compliance for VM Applications with Azure Policy - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/vm-applications-inject-with-policy
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Read VM Application audit compliance within its operating-system filter,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-100-read-vm-application-audit-compliance-within-its-operating-system-filter/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
