# Include other workspace queries in the impact review for one Azure Monitor private-link addition

> Can adding one Log Analytics workspace to AMPLS change the query path for other workspaces?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:16+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Can adding one Log Analytics workspace to AMPLS change the query path for other workspaces?

## Potentially affected

Virtual networks using Azure Monitor Private Link Scope for Log Analytics workspace queries.

## DSE recommendation

Review the full workspace-query population sharing the affected DNS before approving a single workspace's AMPLS addition.

## Article

## Source facts

Log Analytics query endpoints are shared, whereas workspace ingestion endpoints are resource-specific. Adding one workspace to an Azure Monitor Private Link Scope changes the VNet’s shared query endpoint resolution, so queries to all Log Analytics workspaces from that VNet use the private addresses. Microsoft recommends one AMPLS for networks sharing DNS because multiple scopes can overwrite the Azure Monitor zones. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security).

## Applicability

This is the impact boundary of a Log Analytics query-path change, not a statement that every workspace is automatically authorized. AMPLS Open mode permits resources outside the scope; Private Only restricts access to its private-link resources. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security).

## DSE recommendation

Review the full workspace-query population sharing the affected DNS before approving a single workspace’s AMPLS addition. Include operational tools that query a different workspace than the one named in the change. Decide which of those destinations should remain reachable under the selected query access mode. Keep resource-specific ingestion checks separate so successful uploads do not stand in for a query-impact review.

## Verification

From representative affected clients, test authorized queries to both the newly scoped workspace and other required workspaces. Compare their actual results with the approved access-mode decision and retain the resolved query endpoints. Check that the common DNS design has one intended scope owner. Report only the tested destinations as verified; a successful query to the newly added workspace alone does not close the wider change review.

## Official references

[Microsoft Learn: Azure Monitor private-link structure](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security). Source reviewed September 9, 2026.

## Primary reference

- Name: Use Azure Private Link to connect networks to Azure Monitor - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/private-link-security
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Include other workspace queries in the impact review for one Azure Monitor private-link addition,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-520-include-other-workspace-queries-in-the-impact-review-for-one-azure-monitor-private/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
