# Recognize tenant-wide targeting before using the Windows client monitoring installer

> Can a monitored-object DCR target only selected Windows clients inside a Microsoft Entra tenant?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:16+00:00
- Modified: 2026-09-10T00:55:35+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can a monitored-object DCR target only selected Windows clients inside a Microsoft Entra tenant?

## Potentially affected

Windows 11 clients using Azure Monitor Agent's client installer and preview monitored-object operations.

## DSE recommendation

Treat a monitored-object association as a tenant-wide client-installer decision, not an individual-device assignment.

## Article

## Source facts

With Azure Monitor Agent’s Windows client installer, a DCR associated with the tenant’s monitored object applies to all Windows clients running that installer in the tenant. Granular client targeting is unsupported. Agents installed through the VM extension are outside this association’s scope. Microsoft identifies the monitored-object operations as preview-only. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client).

The installer uses Microsoft Entra device tokens rather than the VM extension’s managed identity. Clients must be Entra joined or hybrid joined. This client method does not support private-link monitoring or Azure Monitor Metrics as a destination. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client).

## Applicability

Review Windows 11 clients using Azure Monitor Agent’s client installer and preview monitored-object operations. The method primarily targets continuously connected desktops or workstations; assess laptop limitations and all prerequisites separately.

## DSE recommendation

DSE recommends listing every client already using this installer before associating a rule with the monitored object. Have the collection owner approve that actual population. Do not describe a resource-group name or a deployment tool’s pilot group as a DCR targeting boundary that the service does not provide. Keep extension-managed machines in a separate configuration inventory.

## Verification

In an approved test tenant, inspect the monitored object’s complete association list and compare expected collection on multiple installer-managed clients. Confirm that the resulting destination records identify the intended devices. Review the impact on all existing clients before a production association change; avoid using a tenant-wide change as an unannounced one-device experiment. Preserve the scope decision with the exact rule and association.

## Official references

[Microsoft Learn: Azure Monitor Agent on Windows clients](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client).

## Primary reference

- Name: Set Up the Azure Monitor Agent on Windows Client Devices - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Recognize tenant-wide targeting before using the Windows client monitoring installer,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-160-recognize-tenant-wide-targeting-before-using-the-windows-client-monitoring/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
