# Choose an owned workspace before requiring protected Application Insights tables

> Can an Application Insights managed workspace be reused or configured with protected tables?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-570-choose-an-owned-workspace-before-requiring-protected-application-insights-tables/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:26+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can an Application Insights managed workspace be reused or configured with protected tables?

## Potentially affected

Workspace-based Application Insights resources with automatically created managed Log Analytics workspaces.

## DSE recommendation

Resolve workspace ownership and protected-table requirements before designing additional collection around a managed workspace.

## Article

## Source facts

Application Insights automatically creates a managed Log Analytics workspace when deployment does not specify one. That workspace serves only the creating Application Insights resource: it cannot accept another instance, diagnostic settings or custom logs. Some settings, including quotas, remain adjustable, but the workspace cannot be repurposed. Its managed resource group’s deny assignment blocks protected-table configuration; Microsoft directs sensitive Application Insights data needing that protection to a workspace the customer owns. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/app/managed-workspaces).

## Applicability

Inspect the actual workspace association and managing resource rather than inferring ownership from its name. This decision concerns workspace-based resources and required table protection, not a new classic Application Insights deployment. Define whether the requirement is exclusive application storage, shared collection or protected tables before selecting the destination.

## DSE recommendation

Resolve workspace ownership and protected-table requirements before designing additional collection around a managed workspace. If the requirements need an owned workspace, have the application and monitoring owners plan that association explicitly. Review the intended data access, networking and retention configuration for the destination. Do not respond to the documented restriction by attempting to remove service-managed protection or by repeatedly deploying unsupported data sources.

## Verification

In a representative nonproduction deployment, inspect the linked workspace and verify that it has the ownership model the design requires. Test approved telemetry queries and the required table-protection configuration at the destination. Keep the original workspace until its data and removal obligations have been separately reviewed. Record evidence of the actual association and protection behavior; successfully changing a quota does not establish that the managed workspace supports other uses.

## Official references

[Microsoft Learn: Managed workspaces in Application Insights](https://learn.microsoft.com/en-us/azure/azure-monitor/app/managed-workspaces). Source reviewed September 9, 2026.

## Primary reference

- Name: Application Insights managed workspaces - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/app/managed-workspaces
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose an owned workspace before requiring protected Application Insights tables,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-570-choose-an-owned-workspace-before-requiring-protected-application-insights-tables/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
