# Do not treat a Fabric monitor mirror as an independently retained log copy

> Does mirroring Azure Monitor tables into Fabric create a separate data copy with its own retention?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-593-do-not-treat-a-fabric-monitor-mirror-as-an-independently-retained-log-copy/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:03+00:00
- Modified: 2026-09-10T02:14:32+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Does mirroring Azure Monitor tables into Fabric create a separate data copy with its own retention?

## Potentially affected

Evaluations of the public-preview Mirror Azure Monitor feature in Microsoft Fabric.

## DSE recommendation

Document the shared data lifecycle before presenting the mirror as a retained analytics or investigation dataset.

## Article

## Source facts

Mirror Azure Monitor is a public-preview Fabric feature. It exposes selected Log Analytics tables without copying their data: Fabric reads the underlying files through OneLake shortcuts. Azure Monitor retention and lifecycle policies continue to govern that data. The mirrored item offers an Eventhouse path for KQL and a Lakehouse path for Spark and Power BI. This differs from the retired DCR route that sent ingested data directly to a Fabric destination. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/monitor-cross-domain-fabric).

## Applicability

Use this distinction when evaluating the preview mirror for cross-domain analysis. A useful query surface and an independently retained evidence copy are different requirements; establish which one the proposed design must satisfy.

## DSE recommendation

Document the shared data lifecycle before presenting the mirror as a retained analytics or investigation dataset. Have the monitoring and analytics owners agree the required historical window and compare it with the underlying table policies. Record any separate preservation requirement explicitly instead of assuming that the Fabric item supplies it. Keep the preview evaluation bounded and do not create a new deployment of the retired destination route.

## Verification

Inspect the selected tables and their governing retention configuration. Rehearse representative historical queries through the intended access path and compare the returned period with the approved requirement. Confirm that the architecture record describes a shortcut-backed view rather than a duplicate archive. If longer preservation is required, leave that requirement unresolved until a separately supported design is selected and verified.

## Official references

[Microsoft Learn: Mirror Azure Monitor in Fabric, preview](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/monitor-cross-domain-fabric). Source reviewed September 9, 2026.

## Primary reference

- Name: Mirror Azure Monitor Data in Microsoft Fabric (Preview) - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/monitor-cross-domain-fabric
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not treat a Fabric monitor mirror as an independently retained log copy,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-593-do-not-treat-a-fabric-monitor-mirror-as-an-independently-retained-log-copy/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
