Use a Custom Data Collection Rule for Defender for Servers ingestion
In brief
The article now includes steps for creating a custom data collection rule in the Azure portal and revises guidance for using Azure Policy to create and assign DCRs across subscriptions. Metadata and a next-step link were also updated or removed.
What Defender admins need to know
Administrators get clearer guidance for configuring custom DCRs and managing DCR assignments at scale.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Create a DCR
To create a custom DCR in the Azure portal, follow these steps:
Sign into the Azure portal.
Go to ▸ Monitor ▸ Settings ▸ Data Collection Rules ▸ + Create.
Deploy using Azure Policy
For large environments,If you canmanage many subscriptions, use Azure Policy to automatically create and assign Data Collection Rules (DCRs) forDCRs at scale. The Deploy AMA DCR for Security Events collection policy initiative applies security eventsevent collection rules across multiple subscriptions by using the Deploy AMA DCR for Security Events collection initiative.your environment.
Related content
[!div class="nextstepaction"] Use the data ingestion benefit in Microsoft Defender for Cloud
@@ -2,7 +2,8 @@ title: Use a Custom Data Collection Rule for Defender for Servers ingestion description: Learn how to use Data Collection Rules (DCRs) to customize how Defender for Servers security events are collected and ingested. ms.topic: how-to-ms.date: 12/15/2025+ms.date: 07/03/2026+ms.custom: msecd-doc-authoring-1013 #customer intent: As a security administrator, I want to control which Windows Security events are ingested for Defender for Servers so that I can reduce ingestion volume and costs. ai-usage: ai-assisted ---@@ -27,6 +28,8 @@ Before you create a custom DCR, make sure: ## Create a DCR +To create a custom DCR in the Azure portal, follow these steps:+ 1. Sign into the [Azure portal](https://portal.azure.com). 1. Go to ▸ **Monitor** ▸ **Settings** ▸ **Data Collection Rules** ▸ **+ Create**.@@ -119,11 +122,8 @@ The following example shows a DCR configuration that collects selected Windows S ## Deploy using Azure Policy -For large environments, you can use Azure Policy to automatically create and assign Data Collection Rules (DCRs) for security events across multiple subscriptions by using the [Deploy AMA DCR for Security Events collection](https://github.com/Azure/Microsoft-Defender-for-Cloud/tree/main/Policy/Deploy%20AMA%20DCR%20for%20Security%20Events%20collection) initiative.+If you manage many subscriptions, use Azure Policy to create and assign DCRs at scale. The [Deploy AMA DCR for Security Events collection](https://github.com/Azure/Microsoft-Defender-for-Cloud/tree/main/Policy/Deploy%20AMA%20DCR%20for%20Security%20Events%20collection) policy initiative applies security event collection rules across your environment. ## Related content - [Use the data ingestion benefit in Microsoft Defender for Cloud](data-ingestion-benefit.md)--> [!div class="nextstepaction"]-> [Use the data ingestion benefit in Microsoft Defender for Cloud](data-ingestion-benefit.md) 