You add a new Windows 10 PC named Computer1 that is in a workgroup to an Azure Log Analytics workspace. What action should you perform on Computer1 so Log Analytics can query its events?
Choose an answer
Tap an option to check your answer.
Correct answer: Join Azure AD..
Why this is the answer
Joining Computer1 to Azure AD is the correct action because it enables the device to authenticate with Azure services, including Azure Log Analytics. This allows the Log Analytics agent (which would be installed separately) to securely send data to the workspace. Without Azure AD join, the workgroup PC lacks the necessary identity to establish a trusted connection for data ingestion. Configuring Windows Defender Firewall might be necessary to allow outbound connections for the agent, but it doesn't provide the identity needed for authentication. Creating an event subscription is a method for collecting events from other sources, not for enabling a standalone PC to send its own events to Log Analytics. Installing the Azure Monitor Agent is essential for data collection, but it still requires the device to be able to authenticate with Azure, which Azure AD join facilitates for workgroup computers.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed