# Place configuration and ingestion DCEs in the regions each function requires

> Which region should a data collection endpoint use when agents and their workspace are in different regions?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:01+00:00
- Modified: 2026-09-10T02:08:05+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which region should a data collection endpoint use when agents and their workspace are in different regions?

## Potentially affected

DCR-based Azure Monitor deployments that require data collection endpoints across resource and workspace regions.

## DSE recommendation

Draw configuration retrieval and data ingestion as separate regional paths before assigning DCEs.

## Article

## Source facts

Microsoft assigns different regional roles to DCE components. Configuration access belongs in the monitored resources’ region; log ingestion belongs with the destination Log Analytics workspace, and metric ingestion with the Azure Monitor workspace. For agents sending logs across regions, the documented design uses configuration endpoints in agent regions and ingestion in the workspace region. DCEs are not required for every collection scenario. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-endpoint-overview).

## Applicability

Apply this distinction to DCR-based collection after establishing that the source and connectivity design require a DCE. Inventory agent regions, destination workspace regions, and each endpoint’s purpose. Do not use this article as a claim that every Azure Monitor data path passes through a DCE.

## DSE recommendation

Draw configuration retrieval and data ingestion as separate regional paths before assigning DCEs. For each monitored population, identify where its rules are retrieved and where its records enter the destination pipeline. Have the monitoring and network owners resolve an endpoint selected only because it sits near the agent when that endpoint is intended for workspace ingestion.

## Verification

Inspect the configured endpoint identities and regions against the two paths. Check that representative agents obtain their intended configuration, then trace harmless records to the intended workspace independently. Preserve both results. An endpoint resource that was created successfully is not the acceptance record for regional routing, and successful configuration retrieval should not close an unresolved ingestion-path investigation.

## Official references

[Microsoft Learn: Data collection endpoints in Azure Monitor](https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-endpoint-overview). Source reviewed September 9, 2026.

## Primary reference

- Name: Data collection endpoints in Azure Monitor - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-endpoint-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Place configuration and ingestion DCEs in the regions each function requires,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
