# Separate Azure Monitor workspace quota growth from ingestion-endpoint limits

> Why might a workspace quota increase be insufficient when Prometheus ingestion approaches its limits?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-316-separate-azure-monitor-workspace-quota-growth-from-ingestion-endpoint-limits/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:40+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why might a workspace quota increase be insufficient when Prometheus ingestion approaches its limits?

## Potentially affected

Azure Monitor workspaces ingesting managed Prometheus metrics.

## DSE recommendation

Identify whether the constrained resource is the workspace or its DCR/DCE ingestion path before requesting more capacity.

## Article

## Source facts

Azure Monitor workspace ingestion limits can be increased through a support request. Microsoft recommends monitoring time-series and events-per-minute utilization, and requesting an increase when ingestion approaches eighty percent of its limit. The DCR and DCE limits feeding Prometheus data are separate and cannot be increased; Microsoft instead describes distributing ingestion across additional rules and endpoints. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/metrics/azure-monitor-workspace-scaling-best-practice).

The same guidance recommends examining high-cardinality metrics and removing unnecessary labels to reduce the number of time series. This is a collection-design decision, not an assurance that every label can safely be discarded. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/metrics/azure-monitor-workspace-scaling-best-practice).

## Applicability

Use this capacity review for Azure Monitor workspaces ingesting managed Prometheus metrics. Inventory the workspace and its actual ingestion endpoints before choosing between quota growth and distribution of the collection load.

## DSE recommendation

DSE recommends a separate utilization record for each constrained resource. Include projected series growth and the labels driving it. Ask query and alert owners to approve any label removal before changing collection. Where endpoint distribution is necessary, document which producers move to each path instead of merely adding another endpoint and assuming traffic will rebalance.

## Verification

After an approved pilot, compare utilization and observed ingestion across the original and new paths. Re-run representative queries and alerts against the resulting labels. Retain the before-and-after series counts, endpoint assignment and missing-data checks. Confirm the actual bottleneck improved before closing a workspace quota request or extending the distribution pattern.

## Official references

[Microsoft Learn: Scale Azure Monitor workspaces](https://learn.microsoft.com/en-us/azure/azure-monitor/metrics/azure-monitor-workspace-scaling-best-practice).

## Primary reference

- Name: Best practices for scaling Azure Monitor Workspaces with Azure Monitor managed service for Prometheus - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/metrics/azure-monitor-workspace-scaling-best-practice
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate Azure Monitor workspace quota growth from ingestion-endpoint limits,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-316-separate-azure-monitor-workspace-quota-growth-from-ingestion-endpoint-limits/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
