Your organization is using Microsoft Defender for Cloud to manage security across multiple Azure subscriptions. You need to ensure that all virtual machines in the subscriptions are monitored by Defender for Cloud and that security alerts are sent to the security operations team. You also need to enforce that any new VMs are automatically onboarded to Defender for Cloud. You have a Log Analytics workspace in the central subscription. What should you do?
Enabling auto-provisioning at the management group level is the correct approach because it applies the Log Analytics agent deployment setting to every subscription under that group, guaranteeing unified coverage. When you specify a central workspace, all VMs report to the same Log Analytics workspace, enabling a single pane-of-glass view for security analytics and cross-subscription hunting. Auto-provisioning also automatically installs the agent on new VMs as they are created, closing the coverage gap that exists with manual or policy-based deployment methods.
Why this answer
Enabling auto-provisioning of the Log Analytics agent at the management group scope ensures all VMs across subscriptions are monitored and new VMs are automatically onboarded. Option A is wrong because configuring only the workspace does not auto-provision. Option B is wrong because Azure Policy can enforce agent deployment, but auto-provisioning is simpler and more direct.
Option D is wrong because enabling Defender for Cloud at the subscription level does not automatically install the agent.