BriefingInformationCybersecurityIT

Recognize tenant-wide targeting before using the Windows client monitoring installer

Can a monitored-object DCR target only selected Windows clients inside a Microsoft Entra tenant?

A controlled technology lifecycle progressing from assessment to approved production.
DSE visual intelligenceManaged IT operationsBriefing · 2 min read
Executive summary

What you need to know

Can a monitored-object DCR target only selected Windows clients inside a Microsoft Entra tenant?

Potentially affected

Windows 11 clients using Azure Monitor Agent's client installer and preview monitored-object operations.

DSE recommendation

Treat a monitored-object association as a tenant-wide client-installer decision, not an individual-device assignment.

Source facts

With Azure Monitor Agent’s Windows client installer, a DCR associated with the tenant’s monitored object applies to all Windows clients running that installer in the tenant. Granular client targeting is unsupported. Agents installed through the VM extension are outside this association’s scope. Microsoft identifies the monitored-object operations as preview-only. Microsoft Learn.

The installer uses Microsoft Entra device tokens rather than the VM extension’s managed identity. Clients must be Entra joined or hybrid joined. This client method does not support private-link monitoring or Azure Monitor Metrics as a destination. Microsoft Learn.

Applicability

Review Windows 11 clients using Azure Monitor Agent’s client installer and preview monitored-object operations. The method primarily targets continuously connected desktops or workstations; assess laptop limitations and all prerequisites separately.

DSE recommendation

DSE recommends listing every client already using this installer before associating a rule with the monitored object. Have the collection owner approve that actual population. Do not describe a resource-group name or a deployment tool’s pilot group as a DCR targeting boundary that the service does not provide. Keep extension-managed machines in a separate configuration inventory.

Verification

In an approved test tenant, inspect the monitored object’s complete association list and compare expected collection on multiple installer-managed clients. Confirm that the resulting destination records identify the intended devices. Review the impact on all existing clients before a production association change; avoid using a tenant-wide change as an unannounced one-device experiment. Preserve the scope decision with the exact rule and association.

Official references

Microsoft Learn: Azure Monitor Agent on Windows clients.

Primary reference

Review the official source

Set Up the Azure Monitor Agent on Windows Client Devices - Azure Monitor | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE