Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What is the difference between holding Azure management…
Cyber Security

What is the difference between holding Azure management data in the customer tenant and using optional cross customer rollups?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 10, 2026 Domain: Cyber Security

Holding data in the customer tenant keeps detailed records isolated to that tenant, which is the strongest privacy and governance posture. Optional rollups are different because they aggregate only limited non PII information across multiple customers for higher level review. The key distinction is scope: tenant local data supports operational control, while rollups support fleet level visibility.

Tenant-local records versus fleet-level rollups in Azure

The practical difference is not just where the data sits, but what governance model it supports. Tenant-local management data preserves the strongest boundary because detailed records stay inside one customer tenant, which makes access control, audit, retention, and privacy decisions easier to reason about. Optional cross customer rollups intentionally relax that boundary to give Microsoft and the customer a broader operational view, but only through limited, aggregated, non-PII information. That means the question is really about whether you want depth of control or breadth of visibility.

For teams responsible for privacy, legal review, or regulated environments, the distinction matters because aggregation can change how evidence is handled even when it does not expose full records. In practice, many security teams encounter the governance implications only after reporting requirements, retention expectations, or data residency assumptions have already been set.

How the two models change operational use

Customer-tenant storage is the better fit when the management data is being used as part of incident review, configuration investigation, or tenant-specific accountability. It keeps the record tied to the customer boundary, so the evidence remains directly attributable to that environment. That matters when the organisation needs to answer who changed what, when the change occurred, and whether the data can be retained or deleted on the customer’s terms.

Cross customer rollups serve a different purpose. They are designed for higher level trend analysis, service improvement, and fleet visibility where the individual record is less important than the aggregate pattern. Because the rollup is limited to non-PII data, it supports broad operational insight without turning the dataset into a shared detailed log. The tradeoff is that it cannot replace tenant-local evidence for investigations, customer reporting, or fine-grained control decisions.

  • Use tenant-local data when you need tenant-specific auditability or detailed operational triage.
  • Use rollups when the question is about service-wide trends, not individual customer evidence.
  • Assume the two models answer different governance questions, even if they arise from the same product telemetry.

NIST’s guidance on security and privacy controls is useful here because it separates data governance, auditability, and monitoring concerns rather than treating all telemetry as equivalent. That distinction is what makes the two storage models operationally different, not just technically different.

Where this guidance breaks down is when an organisation expects an aggregated view to support a tenant-level control objective, because the rollup will not carry the detail needed for that decision.

When the distinction becomes material for governance

Tighter tenant isolation often increases administrative overhead, so organisations need to balance evidentiary strength against the convenience of shared operational insight. The tradeoff is especially visible when a team wants one dataset to serve privacy review, operational monitoring, and executive reporting at the same time. Those are related needs, but they are not governed the same way.

One common edge case is misunderstanding what “non-PII” does and does not mean. Non-PII rollups can still be sensitive if they reveal usage patterns, tenant scale, or operational trends, even though they do not expose individual records. Another edge case is contractual or regulatory interpretation: some organisations need explicit approval before any cross customer aggregation is enabled, while others accept it as a normal service optimisation because the content is constrained. The guidance here is consensus driven on the privacy boundary, but practices differ on how much aggregated telemetry should be allowed for internal review.

For a concise overview of broader security governance priorities, the NIST Cybersecurity Framework 2.0 is helpful when you need to position the choice between local evidence and fleet visibility within a wider risk management model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyApplies because the choice affects governance, privacy posture, and risk acceptance.
Recommendation — Use GV.RM to decide whether tenant-local retention or aggregated rollups best fits your risk appetite.
CIS Controls v88 — Audit Log ManagementApplies because tenant-local records support auditability and investigation evidence.
3 — Data ProtectionApplies because the distinction turns on limiting exposure while preserving needed visibility.
Recommendation — Retain detailed tenant-local logs to preserve investigation-ready evidence and accountability. Classify rollup data separately and restrict it to the minimum needed for fleet-level reporting.
NIST SP 800-63Digital Identity GuidelinesNot selected; the question is about telemetry governance, not identity proofing or authenticator assurance.

Practitioner Guidance

What to verify: Confirm whether the reporting use case requires tenant-specific evidence or only trend-level visibility. If the answer involves investigations, audit support, or customer commitments, keep the detailed records tenant-local by default.

Decision rule: Treat cross customer rollups as an optimisation for aggregate insight, not as a substitute evidence source. If a control, contract, or regulator expects traceable records, rollups should not be the primary dataset.

Common mistake: Teams often approve aggregation because the data is “only metadata,” then discover later that the same metadata is needed for tenant-specific accountability. The safer posture is to classify the data by its actual operational use, not by the label attached to it.

Practitioner takeaway: The real choice is whether you need boundary-preserving evidence or fleet-level pattern recognition, and those are different governance objectives that should not be merged for convenience.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 10, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org