Running Azure VMs without the Azure Monitor Agent extension installed
What does ZopNight detect here?
ZopNight flags a running Azure VM that has no Azure Monitor Agent extension, `AzureMonitorLinuxAgent` or `AzureMonitorWindowsAgent`. Host metrics such as CPU arrive without setup, but guest memory, logs and events need that agent and a data collection rule. The legacy Log Analytics agent retired on 31 August 2024.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-268 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | no Azure Monitor Agent extension on the VM |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read · Microsoft.Compute/virtualMachines/extensions/read |
Where it applies
Host metrics stop at the hypervisor
Azure Monitor separates two views of a VM. Host-level data comes from the Hyper-V session running the guest and covers CPU, network and disk utilization; you get it automatically. Guest-level data covers the operating system and applications inside the VM: memory pressure, disk space, event logs, syslog and process health.
Guest data needs an agent. The Azure Monitor Agent is the supported one, and it collects whatever its data collection rules specify. The older Log Analytics agent was retired on 31 August 2024.
Checking a VM for the agent
az vm extension list --resource-group my-rg --vm-name my-vm \ --query "[?contains(name, 'AzureMonitor')].name" -o tsvAzureMonitorLinuxAgent or AzureMonitorWindowsAgent means the agent is installed. It still
needs an associated data collection rule before any data flows.
What the finding requires
- The VM is provisioned successfully or running.
- ZopNight’s list of VMs with the Azure Monitor Agent extension (
AzureMonitorLinuxAgentorAzureMonitorWindowsAgent) was retrieved and this VM is not in it. Whether a data collection rule is associated is not checked, so a VM with the agent but no rule is not flagged.
Both come from Azure itself; tags are not read. No metric threshold or window applies.
When ZopNight stays quiet
VMs in other provisioning states are skipped. If the monitoring inventory was not available for a VM, ZopNight has no evidence and raises nothing. Boot diagnostics is a different setting with its own check, Azure VM Diagnostics Not Enabled, and does not satisfy this one.
Blind spots, paid for in ingestion
The estimate is a fixed $0 per month. Guest monitoring adds Log Analytics ingestion and retention charges for whatever the data collection rules send. The risk of skipping it is that a VM fills its disk or runs out of memory without an alert.
Enabling guest monitoring
- In the portal, open the VM, select Insights and enable it; VM insights uses the Azure Monitor Agent with a data collection rule.
- Or install the agent yourself:
az vm extension set --resource-group my-rg --vm-name my-vm \ --name AzureMonitorLinuxAgent --publisher Microsoft.Azure.Monitor \ --enable-auto-upgrade true- Associate a data collection rule that sends the counters and logs you need to a Log Analytics workspace.
- Add alerts for memory, disk space and heartbeat loss.
- Remove any leftover Log Analytics agent extension from before the 2024 retirement.