Distinguish a Policy reevaluation from a fresh guest configuration audit

An on-demand Azure Policy evaluation reads the latest Machine Configuration result; it does not initiate another check inside the machine.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

An on-demand Azure Policy evaluation reads the latest Machine Configuration result; it does not initiate another check inside the machine.

Potentially affected

Azure Policy evaluations of Machine Configuration results for Azure and Arc-enabled machines.

DSE recommendation

Verify the underlying guest audit's freshness before using a reevaluated policy result to close a configuration change.

Source facts

An on-demand Azure Policy evaluation retrieves the latest result held by the Machine Configuration resource provider. It does not trigger a new operation inside the machine; the resulting policy status is written to Azure Resource Graph.

The agent checks for assignment changes every five minutes and normally rechecks an assigned configuration every fifteen minutes. Multiple configurations run sequentially, so a long-running one can delay the others. Microsoft Learn.

Applicability

Identify the guest assignment, machine and configuration change being assessed. Keep the time of policy reevaluation separate from the time represented by the guest’s result.

DSE recommendation

DSE recommends a closure record that identifies the underlying audit and its relationship to the change window. If the latest result predates the change, leave the verification pending and investigate the guest audit’s progress. Do not repeatedly request policy evaluation as a substitute for confirming that the in-machine work completed. Review a slow configuration’s effect on the other assigned checks before treating a delayed result as a policy-engine failure.

Verification

After an approved test change, observe the guest audit and the subsequent reported policy state. Retain the assignment identity and available timing evidence for both stages. Confirm that the result used for closure reflects the intended configuration. Record any missing or ambiguous timing rather than describing a refreshed portal view as a newly executed guest test.

Official references

Microsoft Learn: Azure Machine Configuration prerequisites. Source retrieved September 9, 2026.

Primary reference

Review the official source

Azure Machine Configuration prerequisites - Azure Machine Configuration | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE