Setting the file. One moment.
Subchapter 12.9
workflows/essential-machine-management/references/emm-enable-flow-portal-guidance.mdMarkdown3 KBView on GitHub
Step-by-step guide for enabling Essential Machine Management through the Azure portal UI.
| Property | Value |
|---|---|
| Portal blade | EnableMachineManagement.ReactView |
| Extension | Microsoft_Azure_Computehub |
| Portal path | Compute infrastructure → Monitoring+Operations → Essential Machine Management → Enable |
| Resource type | Microsoft.ManagedOps/ManagedOps |
The portal enable flow is a multi-tab wizard with 4 tabs:
Select the target subscription and managed identity.
| Field | Description | Required |
|---|---|---|
| Subscription | The subscription to enable EMM for. Shows VM and Arc machine counts per subscription. | ✅ |
| User-assigned managed identity | UAMI with Contributor on the subscription. Used for onboarding VMs. | ✅ |
Validation displayed:
💡 Tip: If roles are missing, the UI shows exactly which roles are needed. Assign them before proceeding.
Select or create the monitoring workspaces.
| Field | Description | Required |
|---|---|---|
| Log Analytics workspace | Collects log data (Change Tracking & Inventory). Can create new inline. | ✅ |
| Azure Monitor workspace | Collects metrics data (VM Insights). Can create new inline. | ✅ |
Notes:
Optional security add-ons.
| Feature | Description | Cost |
|---|---|---|
| Foundational CSPM | Agentless, risk-prioritized cloud security posture insights. Always included. | Free |
| Defender CSPM | Advanced CSPM with attack path analysis. Optional toggle. | Paid |
| Defender for Cloud | Comprehensive server protection with EDR, vulnerability management, file integrity monitoring. Optional toggle. | Paid |
Displays a summary of all selections:
Clicking Enable triggers:
ManagedOps_{uamiName}_{subscriptionId}