Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Applies to: ✔️ Windows VMs ✔️ Linux VMs ✔️ Windows Registry ✔️ Windows Files ✔️ Linux Files ✔️ Windows Software
This article provides detailed procedures on how to enable Azure Change Tracking and Inventory at scale by using Azure Policy.
Prerequisite
Before you enable Change Tracking and Inventory, ensure that you create a data collection rule (DCR) or use an existing one.
Enable Azure Change Tracking and Inventory at scale
By using the deploy-if-not-exists (DINE) policy, you can enable Change Tracking with the Azure Monitor Agent at scale and in the most efficient manner.
Sign in to the Azure portal and select Change Tracking and Inventory.
On the Change Tracking and Inventory Center | Machines pane, under Manage, select Policy.
On the Change Tracking and Inventory Center | Policy pane, under the filter Definition Type, select Initiative. In the Category filter, select Change Tracking and Inventory to see three policies:
Azure Arc-enabled virtual machines
Azure Virtual Machine Scale Sets
Virtual machines
Select Enable ChangeTracking and Inventory for virtual machines to enable Change Tracking on Azure VMs. This step includes three policies. Each policy is determined by the operating system type of the selected machine:
Select Assign initiative to assign the policy to a resource group. An example policy is Assign Built-In User-Assigned Managed Identity to Virtual Machines.
Note
The resource group contains VMs. When you assign the policy, it enables Change Tracking at scale to a resource group. The VMs that are onboarded to the same resource group automatically have Change Tracking enabled.
On the Enable ChangeTracking and Inventory for virtual machines pane, enter the following options:
- On the Basics tab, you can define the scope. Select the ellipsis to configure a scope.
- On the Scope pane, enter Subscription and Resource Group values.
- On the Parameters tab, select the option in Bring Your Own User-Assigned Managed Identity.
- Enter the Data Collection Rule Resource Id value. Learn more about how to obtain the data collection rule resource ID after you create the data collection rule.
- Select Review + create.
Related content
- Learn more about how to enable Change Tracking and Inventory at scale by using the Azure portal.