Include other workspace queries in the impact review for one Azure Monitor private-link addition

Can adding one Log Analytics workspace to AMPLS change the query path for other workspaces?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Can adding one Log Analytics workspace to AMPLS change the query path for other workspaces?

Potentially affected

Virtual networks using Azure Monitor Private Link Scope for Log Analytics workspace queries.

DSE recommendation

Review the full workspace-query population sharing the affected DNS before approving a single workspace's AMPLS addition.

Source facts

Log Analytics query endpoints are shared, whereas workspace ingestion endpoints are resource-specific. Adding one workspace to an Azure Monitor Private Link Scope changes the VNet’s shared query endpoint resolution, so queries to all Log Analytics workspaces from that VNet use the private addresses. Microsoft recommends one AMPLS for networks sharing DNS because multiple scopes can overwrite the Azure Monitor zones. Microsoft Learn.

Applicability

This is the impact boundary of a Log Analytics query-path change, not a statement that every workspace is automatically authorized. AMPLS Open mode permits resources outside the scope; Private Only restricts access to its private-link resources. Microsoft Learn.

DSE recommendation

Review the full workspace-query population sharing the affected DNS before approving a single workspace’s AMPLS addition. Include operational tools that query a different workspace than the one named in the change. Decide which of those destinations should remain reachable under the selected query access mode. Keep resource-specific ingestion checks separate so successful uploads do not stand in for a query-impact review.

Verification

From representative affected clients, test authorized queries to both the newly scoped workspace and other required workspaces. Compare their actual results with the approved access-mode decision and retain the resolved query endpoints. Check that the common DNS design has one intended scope owner. Report only the tested destinations as verified; a successful query to the newly added workspace alone does not close the wider change review.

Official references

Microsoft Learn: Azure Monitor private-link structure. Source reviewed September 9, 2026.

Primary reference

Review the official source

Use Azure Private Link to connect networks to Azure Monitor - Azure Monitor | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE