# Distinguish a Policy reevaluation from a fresh guest configuration audit

> An on-demand Azure Policy evaluation reads the latest Machine Configuration result; it does not initiate another check inside the machine.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:11+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

An on-demand Azure Policy evaluation reads the latest Machine Configuration result; it does not initiate another check inside the machine.

## Potentially affected

Azure Policy evaluations of Machine Configuration results for Azure and Arc-enabled machines.

## DSE recommendation

Verify the underlying guest audit's freshness before using a reevaluated policy result to close a configuration change.

## Article

## Source facts

An on-demand Azure Policy evaluation retrieves the latest result held by the Machine Configuration resource provider. It does not trigger a new operation inside the machine; the resulting policy status is written to Azure Resource Graph.

The agent checks for assignment changes every five minutes and normally rechecks an assigned configuration every fifteen minutes. Multiple configurations run sequentially, so a long-running one can delay the others. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/02-setup-prerequisites).

## Applicability

Identify the guest assignment, machine and configuration change being assessed. Keep the time of policy reevaluation separate from the time represented by the guest’s result.

## DSE recommendation

DSE recommends a closure record that identifies the underlying audit and its relationship to the change window. If the latest result predates the change, leave the verification pending and investigate the guest audit’s progress. Do not repeatedly request policy evaluation as a substitute for confirming that the in-machine work completed. Review a slow configuration’s effect on the other assigned checks before treating a delayed result as a policy-engine failure.

## Verification

After an approved test change, observe the guest audit and the subsequent reported policy state. Retain the assignment identity and available timing evidence for both stages. Confirm that the result used for closure reflects the intended configuration. Record any missing or ambiguous timing rather than describing a refreshed portal view as a newly executed guest test.

## Official references

[Microsoft Learn: Azure Machine Configuration prerequisites](https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/02-setup-prerequisites). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure Machine Configuration prerequisites - Azure Machine Configuration | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview/02-setup-prerequisites
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Distinguish a Policy reevaluation from a fresh guest configuration audit,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-285-distinguish-a-policy-reevaluation-from-a-fresh-guest-configuration-audit/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
