Loading...

Announcing Azure Monitoring Agent support in Azure Landing Zones

Announcing Azure Monitoring Agent support in Azure Landing Zones

Introduction

 

Hello and welcome to another blog post about Azure Landing Zones, the best practice framework for accelerating your cloud adoption journey. In this post, I will share with you some of the latest updates and enhancements that we have made to Azure Landing Zones.
 
One of the main components of Azure Landing Zones is the Azure Monitoring Agent (AMA), which enables you to collect and analyze data from your virtual machines, virtual machine scale sets, and hybrid resources. AMA provides a unified agent experience for Azure Monitor, Azure Security Center, Azure Sentinel, and other services. AMA replaces the legacy Log Analytics agent and Dependency agent, and offers better performance, reliability, and security.
 
We are happy to announce that all the implementation methods, including Terraform and Bicep have been updated and Azure Landing Zones is now exclusively using AMA for all its monitoring scenarios. This means that you can benefit from the latest features and capabilities of AMA, such as the ability to send custom logs and metrics, use Azure Arc to monitor hybrid resources, and leverage Azure Policy to deploy and manage AMA at scale.
 
 
As MMA is deprecating, as of the 31st of August 2024, please make sure that you are working towards migrating to AMA to avoid falling out of support. We're retiring the Log Analytics agent in Azure Monitor on 31 August 2024 | Azure updates | Microsoft Azure

 

Key Updates and Enhancements

 

Since January 2024, the Portal Accelerator has been utilizing AMA and has received a significant update. Let's explore the specifics of the recent updates.
 

Centralization of the User Assigned Managed Identity

 

One of the most noteworthy advancements is the centralized approach to User Assigned Managed Identities (UAMI). Here are the key highlights:
 
  • Centralized UAMI: Azure Landing Zones now utilizing a single, centralized UAMI for AMA, enhancing manageability and scalability.
  • Reliability: After the UAMI is created, it's replicated globally, and credential requests happen within the VM/VMSS's region instead of the UAMI region. Therefore, if the VM is in EastUS and the UAMI in WestUS, whenever the VM needs the UAMI credential, the request is completely fulfilled in EastUS.
  • Scalability: Caching is enabled to support large-scale deployments. Managed identity limits for user assigned identity assignment remain the same regardless if you use single UAMI versus serval UAMI since rate limiting is done based on the VM/VMSS receiving the assignment not on the UAMI being assigned. This enables the convenience of managing a single identity that is both scalable and reliable.
  • Protection: Added new custom policy Do not allow deletion of specified resource and resource type that provides a safeguard against accidental removal of the User Assigned Managed Identity used by AMA. Assigned at the Platform Management Group, it blocks delete calls using the deny action effect.

 

New Policies and Built-in Initiatives

 

To support the seamless integration of AMA, several policy updates have been made:
 
  • Deny Action Delete Policy: A new policy has been introduced that denies the deletion of the UAMI used for AMA, adding an extra layer of security.
  • Policy Initiatives Updates: Built-in policy initiatives for VM Insights, Change Tracking, and Microsoft Defender for Cloud (MDfC) Defender for SQL have been updated to support a single centralized UAMI.
  • Feature Flag: The restriction that enforces a UAMI per subscription is lifted by setting the restrictBringYourOwnUserAssignedIdentityToSubscription feature flag to false, enabling the use of a single centralized UAMI.

 

For more details on the policy changes please review What's New.

 

Brownfield Migration Guidance

 

Migrating existing environments to AMA involves several steps, which are comprehensively covered in the new brownfield migration guidance.
 
Here's a breakdown of the process: 

 

  • Assess current state: Conduct a thorough analysis of your existing environment to identify dependencies and custom configurations.
  • Update Azure Landing Zones: guidance and automation tools help streamline the update process for Azure Landing Zones components
  • Removing MMA and additional steps: It is crucial to be aware of other settings in your environment that may necessitate further considerations and steps when planning to migrate. While the final phase involves removing the Microsoft Monitoring Agent and addressing, you may need to address additional requirements discovered during the initial assessment, we have included references to already existing documentation to help with the next steps

 

Automation Tools

 

To facilitate the transition, we have developed a PowerShell script designed to update Azure Landing Zones portal accelerator deployments to support AMA. This script reduces the manual effort required and ensures a smooth migration process. Several tasks that are automated:
 
  • Update Policies and Initiatives.
  • Delete outdated Policy Assignments.
  • Deploy a User Assigned Managed Identity for the AMA agent.
  • Deploys Data Collection Rules for VMInsights, ChangeTracking and MDfC Defender for SQL.
  • Assign new Policies and Initiatives.
  • Remove Legacy Solutions
  • Create remediation tasks for the newly assigned Policies and initiatives.
  • Remove obsolete User Assigned Managed Identities (that were deployed with releases starting 2024-01-31 until 2024-04-24)

 

Conclusion

 

The recent updates to Azure Landing Zones, with a focus on the Azure Monitoring Agent, bring significant improvements in manageability, scalability, and security. The comprehensive brownfield migration guidance and automation tools provide a clear pathway for existing environments to transition seamlessly to AMA. By leveraging these enhancements, organizations can better manage their Azure environments and ensure they remain compliant with the latest best practices.
 
Stay tuned for more updates and detailed guides on implementing and optimizing your Azure Landing Zones.

Published on:

Learn more
Azure Governance and Management Blog articles
Azure Governance and Management Blog articles

Azure Governance and Management Blog articles

Share post:

Related posts

{How to} Create Azure Communication Services for Dynamics 365 Customer Service Omnichannel

Hello Everyone,Today I am going to show how to subscribe to Azure Communication Services on Azure Portal.Let's get's started.Let's say you hav...

4 hours ago

Upgrade to Azure Synapse runtimes for Apache Spark 3.4 & previous runtimes deprecation

It is important to stay ahead of the curve and keep services up to date. That's why we encourage all Azure Synapse customers with Apache ...

1 day ago

Using Keycloak with Azure AD to integrate AKS Cluster authentication process

  Introduction Integrating Azure Kubernetes Service (AKS) with Keycloak through Azure Active Directory (Azure AD) as an intermediary lev...

1 day ago

Dev Proxy v0.19 with simulating LLM APIs and new Azure API Center integrations

We're excited to share the launch of Dev Proxy v0.19 to help you to build robust apps connected to APIs. The post Dev Proxy v0.19 with simulat...

1 day ago

PostgreSQL with Local Small Language Model and In-Database Vectorization | Azure

Improve search capabilities for your PostgreSQL-backed applications using vector search and embeddings generated in under 10 milliseconds with...

1 day ago

Convert speech to text using Azure Speech service in Power Automate Flow

Azure provides Speech Services that let developers add advanced speech features to achieve complex functionality, including Speech-to-Text. Wi...

2 days ago

Azure API Center: Centralizing API Management for Enhanced Discovery and Governance

  Have you ever thought about having a single place to manage all your APIs? It could make it easier to find and control your services. ...

2 days ago

Azure SDK Release (June 2024)

The Azure SDKs release every month. This post includes the month's highlights and release notes. The post Azure SDK Release (June 2024) appear...

3 days ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy