# Identify the intended Application Insights resource in preview AMA telemetry

> When does AMA-based OTLP ingestion require the microsoft.applicationId resource attribute?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-571-identify-the-intended-application-insights-resource-in-preview-ama-telemetry/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:25+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: IT
- Reading time: 2 minutes

## What you need to know

When does AMA-based OTLP ingestion require the microsoft.applicationId resource attribute?

## Potentially affected

Nonproduction evaluations of preview AMA-based OTLP ingestion using a DCR that references Application Insights.

## DSE recommendation

Map the application attribute to the intended Application Insights resource before evaluating whether the test data is correctly separated.

## Article

## Source facts

AMA-based OTLP ingestion is preview and Microsoft does not recommend it for production workloads. Its application configuration requires microsoft.applicationId when Application Insights created the DCR or when a manually created DCR includes an Application Insights ID. The attribute uses the GUID after InstrumentationKey= in the connection string, enabling separation by Application Insights resource. The source specifies AMA 1.38.1 or later on Windows and 1.37.0 or later on Linux. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/containers/opentelemetry-ingest-agent).

## Applicability

Use this attribution check in a bounded preview evaluation with an Application Insights-linked DCR. Do not extend the attribute requirement to every manually orchestrated ingestion arrangement without checking whether that linkage exists.

## DSE recommendation

Map the application attribute to the intended Application Insights resource before evaluating whether the test data is correctly separated. Have the application owner compare the actual runtime attribute with the chosen resource, rather than copying an identifier from another environment. Record the DCR linkage and installed agent version with the test configuration. Keep this identity mapping separate from network reachability.

## Verification

Send an approved recognizable test event and inspect the configured attribute and expected Application Insights destination. Where two applications share infrastructure, test each intended attribution separately and check for misplaced records. Preserve the event identity, configuration and observed destination without copying unnecessary connection details into broadly shared evidence. Accept the mapping only after the intended resource can be distinguished from another test environment.

## Official references

[Microsoft Learn: AMA OTLP ingestion, preview](https://learn.microsoft.com/en-us/azure/azure-monitor/containers/opentelemetry-ingest-agent). Source reviewed September 9, 2026.

## Primary reference

- Name: Ingest OTLP Data into Azure Monitor with AMA (Preview) - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/containers/opentelemetry-ingest-agent
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Identify the intended Application Insights resource in preview AMA telemetry,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-571-identify-the-intended-application-insights-resource-in-preview-ama-telemetry/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
