# Check which VMs lose alert coverage when subscription recommendations skip host metrics

> Does guest-only subscription alerting in Monitoring Coverage include VMs without OTel collection?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-206-check-which-vms-lose-alert-coverage-when-subscription-recommendations-skip-host/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:30+00:00
- Modified: 2026-09-10T01:20:45+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: IT
- Reading time: 2 minutes

## What you need to know

Does guest-only subscription alerting in Monitoring Coverage include VMs without OTel collection?

## Potentially affected

Preview Azure Monitor Monitoring Coverage VM recommended alerts, particularly subscription scope with host metric rules skipped.

## DSE recommendation

Compare the intended subscription VM population with the actual OTel-enabled population before approving guest-only coverage.

## Article

## Source facts

Monitoring Coverage is an Azure Monitor preview. Its subscription-wide VM alert option includes existing and future VMs, creates one rule per subscription, and requires a user-assigned managed identity plus Monitoring Contributor. Selected-resource scope instead creates one rule per selected VM. In subscription scope, choosing to skip host metric rules leaves guest alerts only for VMs with Azure Monitor Agent OTel collection; VMs without that telemetry remain uncovered. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/monitoring-coverage).

## Applicability

This is a scope decision within the preview recommended-alert workflow, not a general assessment of every alert already deployed to a subscription. A subscription label alone should not be the acceptance criterion for the proposed guest-only configuration.

## DSE recommendation

Compare the intended subscription VM population with the actual OTel-enabled population before approving guest-only coverage. List any exceptions and decide whether they should receive appropriate host alerts, have guest collection established, or remain an explicitly accepted gap. Assign ownership for checking newly created VMs against that decision. Keep notification configuration and the telemetry population as separate review items.

## Verification

Inspect the proposed scope and the host-rule selection on Review + Enable. Compare representative VMs with and without the required collection and document which proposed rules can cover each. Reconcile the resulting population with the approved inventory rather than assuming subscription scope is exhaustive. Retain the selected settings and exceptions; this review should not claim that an alert fired or reached an operator unless that separate test was performed.

## Official references

[Microsoft Learn: Monitoring Coverage preview](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/monitoring-coverage). Source reviewed September 9, 2026.

## Primary reference

- Name: Monitoring coverage in Azure Monitor (preview) - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/monitoring-coverage
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check which VMs lose alert coverage when subscription recommendations skip host metrics,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-206-check-which-vms-lose-alert-coverage-when-subscription-recommendations-skip-host/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
