# Backfill each member policy when deploying a diagnostic-settings initiative

> Does assigning a diagnostic-settings initiative automatically configure every existing resource?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:10+00:00
- Modified: 2026-09-10T00:55:35+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does assigning a diagnostic-settings initiative automatically configure every existing resource?

## Potentially affected

Supported Azure resources receiving diagnostic settings through built-in logging policies or initiatives.

## DSE recommendation

Track remediation for every applicable member policy and compare existing-resource coverage with the new-resource path.

## Article

## Source facts

For the documented diagnostic-settings deployment, assignment without remediation applies to resources created afterward, not the existing population. Existing resources require a remediation task. An initiative requires a task for each constituent policy, and the task identifies that member through its definition-reference ID. Microsoft provides a Remediation tasks view for tracking the resulting work. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/diagnostic-settings-policy-built-in).

## Applicability

Use this backfill check for built-in diagnostic-setting initiatives covering supported resource types. Separate assignment creation, member-policy remediation and the actual arrival of expected logs; each is a different acceptance question.

## DSE recommendation

Track remediation for every applicable member policy and compare existing-resource coverage with the new-resource path. Build the expected list from the initiative’s definitions and the resource inventory, rather than assuming that one completed task represents the whole initiative. Have the monitoring owner review the destination and intended categories before backfilling existing resources. Preserve unresolved member policies as visible rollout work.

## Verification

Compare task records and definition-reference IDs with the expected member list. Inspect representative existing resources of each applicable type for the intended diagnostic setting, then verify that an approved test event reaches the selected destination. Check a newly created test resource separately. Do not report full historical-population coverage from a successful initiative assignment or a single resource’s logs; document remaining gaps by resource type and owning task.

## Official references

[Microsoft Learn: Built-in policies for diagnostic settings](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/diagnostic-settings-policy-built-in). Source reviewed September 9, 2026.

## Primary reference

- Name: Enable Diagnostic Settings by Category Group Using Built-in Policies - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/platform/diagnostic-settings-policy-built-in
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Backfill each member policy when deploying a diagnostic-settings initiative,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-166-backfill-each-member-policy-when-deploying-a-diagnostic-settings-initiative/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
