Skip to main content
compliance · azure

Running Azure VMs without the Azure Monitor Agent extension installed

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags a running Azure VM that has no Azure Monitor Agent extension, `AzureMonitorLinuxAgent` or `AzureMonitorWindowsAgent`. Host metrics such as CPU arrive without setup, but guest memory, logs and events need that agent and a data collection rule. The legacy Log Analytics agent retired on 31 August 2024.

Signal and threshold

How ZopNight evaluates Running Azure VMs without the Azure Monitor Agent extension installed.
Field Value
Rule IDsRC-268
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Thresholdno Azure Monitor Agent extension on the VM
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read · Microsoft.Compute/virtualMachines/extensions/read

Host metrics stop at the hypervisor

Azure Monitor separates two views of a VM. Host-level data comes from the Hyper-V session running the guest and covers CPU, network and disk utilization; you get it automatically. Guest-level data covers the operating system and applications inside the VM: memory pressure, disk space, event logs, syslog and process health.

Guest data needs an agent. The Azure Monitor Agent is the supported one, and it collects whatever its data collection rules specify. The older Log Analytics agent was retired on 31 August 2024.

Checking a VM for the agent

Terminal window
az vm extension list --resource-group my-rg --vm-name my-vm \
--query "[?contains(name, 'AzureMonitor')].name" -o tsv

AzureMonitorLinuxAgent or AzureMonitorWindowsAgent means the agent is installed. It still needs an associated data collection rule before any data flows.

What the finding requires

  1. The VM is provisioned successfully or running.
  2. ZopNight’s list of VMs with the Azure Monitor Agent extension (AzureMonitorLinuxAgent or AzureMonitorWindowsAgent) was retrieved and this VM is not in it. Whether a data collection rule is associated is not checked, so a VM with the agent but no rule is not flagged.

Both come from Azure itself; tags are not read. No metric threshold or window applies.

When ZopNight stays quiet

VMs in other provisioning states are skipped. If the monitoring inventory was not available for a VM, ZopNight has no evidence and raises nothing. Boot diagnostics is a different setting with its own check, Azure VM Diagnostics Not Enabled, and does not satisfy this one.

Blind spots, paid for in ingestion

The estimate is a fixed $0 per month. Guest monitoring adds Log Analytics ingestion and retention charges for whatever the data collection rules send. The risk of skipping it is that a VM fills its disk or runs out of memory without an alert.

Enabling guest monitoring

  1. In the portal, open the VM, select Insights and enable it; VM insights uses the Azure Monitor Agent with a data collection rule.
  2. Or install the agent yourself:
Terminal window
az vm extension set --resource-group my-rg --vm-name my-vm \
--name AzureMonitorLinuxAgent --publisher Microsoft.Azure.Monitor \
--enable-auto-upgrade true
  1. Associate a data collection rule that sends the counters and logs you need to a Log Analytics workspace.
  2. Add alerts for memory, disk space and heartbeat loss.
  3. Remove any leftover Log Analytics agent extension from before the 2024 retirement.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·