Azure Monitor: Three due dates between August 31 and September 30, 2026
Three Deadlines Azure Monitor deadlines will occur between August 31 and September 30, 2026: a managed identity requirement to link a storage account to a Log Analytics workspace, the end of support for the HTTP Data Collector in theAPI , and the end of support for legacy authentication in Container Insights. None of these three deadlines stops data ingestion: regarding the September 14 deadline, Microsoft states that existing ingestion will continue to function; the other two either block a configuration operation or end support, with no page describing a halt to data collection. The pages bearing these dates, however, describe mechanisms that do halt log reporting, and none of them are tied to these deadlines.
| Date | Component | Effect |
|---|---|---|
| August 31, 2026 | Log Analytics | Without a managed identity in the workspace, you cannot add or update a linked storage account. |
| September 14, 2026 | API HTTP Data Collector | End of support. The existing deployment continues, and theAPI now receives only critical security patches. |
| September 30, 2026 | Container Insights | Clusters that still use legacy authentication are no longer supported. |

Managed identity is becoming a requirement for linking a storage account
Effective August 31, 2026, a Log Analytics workspace must have a managed identity in order to add or update a linked storage account used for recorded queries and recorded log alert queries. The restriction applies to the operation itself: creating a link, as well as updating an existing link.
There are two requirements, not just one. The first is a managed identity in the workspace. The second is assigning a role to that identity in the storage account: Storage Table Data Contributor. A workspace with a managed identity that does not have this assignment remains blocked. The storage account must also be located in the same region as the workspace.
Linked storage accounts for custom logs and IIS logs have not been created since June 30, 2025, and existing ones were unlinked on November 1, 2025. The only items still affected by the deadline are links of the type Query and Alerts, those used to encrypt logged requests and alerts using a client-managed key.
The page containing this requirement states that it will take effect no earlier than August 31, 2026. The block may therefore begin on that date or later.
Note: Until the application has started, the workspace does not use the managed identity to authenticate with private storage. Microsoft recommends that you do not remove the current authentication method until it has announced that managed identities are active for this authentication. Assigning the identity and role is a preparatory step, not a switchover.
API HTTP Data Collector: Support Ends, Ingestion Continues
Support for the HTTP Data CollectorAPI will end on September 14, 2026. The page migration describes the impact on ingestion.
The existing feed continues to function, but theAPI receives only critical security patches.
The same page revisits this point regarding the date itself: on September 14, 2026, theAPI will be taken offline, but ingestion will continue for TLS-compatible clients. It adds that you should verify a client’s TLS configuration before assuming that its ingestion is secure, regardless of the migration chosen.
An earlier date, however, marked the end of data ingestion. On March 1, 2026, the endpoint stopped accepting legacy TLS versions: a client that does not negotiate TLS 1.2 or a later version can no longer ingest data as of that date. This is the first thing to check if a script is no longer reporting anything.
Identify what is still using this API
Microsoft provides three methods for locating the relevant tables. In the portal, tables populated by this API display Custom table (classic) as a property Type. Through the log managementAPI , their tableSubType is worth Classic, which a Azure CLI command lists directly:
az monitor log-analytics workspace table list \ --resource-group myResourceGroupName --workspace-name myWorkspaceName \ --query "[?schema.tableSubType=='Classic'].{Name:name, SubType:schema.tableSubType}" -o tableFinally, the records written by this API include SourceSystem to the value RestAPI. In the code and scheduled tasks, the endpoint to look for is ods.opinsights.azure.com/api/logs, called with api-version=2016-04-01.
What the migration change
Replacement is the log ingestionAPI . It requires two resources that the HTTP Data CollectorAPI did not require: a data collection endpoint and a data collection rule. It accepts 1 MB per call, compared to 30 MB for the old version—so any submission larger than 1 MB must be split into multiple parallel calls.
Important limitations to be aware of before you begin. Migrating a table while continuing to ingest data via the old API is not recommended: repeated data type changes and schema changes to these tables can cause errors. And for a table that has already been migrated but is still being populated by the old API, making a schema change viaAPI Tables or via “Modify Schema” will interrupt the legacy ingestion.
One final scope-related note: the HTTP Data CollectorAPI does not support Azure Monitor Private Link Scope. For a workspace behind a private link, Microsoft recommends using the log ingestionAPI .
Container Insights: Clusters Using Legacy Authentication Are No Longer Supported
Container Insights’ legacy authentication is being phased out. After September 30, 2026, clusters that still use it will no longer be supported. This is a support policy and not a technical shutdown: the documentation does not mention any interruption in data collection on that date. The consequence is operational and is relevant to anyone running containers in production: on a cluster that has remained on legacy authentication, Microsoft Support will not handle monitoring incidents.
However, there is a documented mechanism that stops data collection on these clusters, and it has no set date: the rotation of the Log Analytics workspace keys. Monitoring then stops reporting data, and you must disable and then re-enable the Container Insights add-on to restore data flow using the new keys. Managed identity authentication does not use these keys.
Two Resource Graph queries list these clusters—one for AKS clusters and the other for Kubernetes clusters connected via Azure Arc: they include those that useAADAuth is not at true. The relevant query verifies the switchover, since a migrated cluster no longer appears in its results.
On AKS, the switchover begins by disabling monitoring, then upgrades the cluster to managed identity before reactivating the add-on; data collection may be interrupted while this process is underway. Three cloud providers support this feature: the cloud public, Azure Government, and Microsoft Azure cloud operated by 21Vianet. For a cluster with a user-assigned identity, only the cloud public cloud is supported.
Switching to managed identity provides access to the latest Container Insights features, including syslog collection and high-volume logging.
The ingestion interruptions documented by Microsoft
The pages cited also describe mechanisms that halt the upward movement of logs, without any of them being tied to one of the three deadlines:
- an HTTP Data Collector client from theAPI that does not support TLS 1.2 or later, as of March 1, 2026;
- a schema change made to a migrated table that is still being populated by the old API ;
- Rotating workspace keys on a Container Insights cluster that is still using legacy authentication.
The first two are used to verify the configuration of clients and tables. The third is phased out with the transition to managed identity.
Checks to Be Conducted by September 30, 2026
- Check the TLS version of clients that call the HTTP Data CollectorAPI . This check applies to data ingestion that may have been stopped as of March 1, 2026, and is not dependent on any of the three deadlines.
- List the tables that
tableSubTypeis worthClassic, and then decide for each one between migration table-only or side-by-side implementation. A migrated table cannot be restored to its previous state. - Assign a managed identity to Log Analytics workspaces that have a connection of type
QueryorAlerts, and assign the role to that identityStorage Table Data Contributorto the storage account—without removing the existing authentication method. - Run the two Resource Graph queries and schedule the failover of the listed clusters, taking into account the interruption in data collection during the operation.
These four checks are part of the routine maintenance of a base Azure, which we describe on our Infrastructure and Cloud page.
Microsoft Sources
- Migrating from the HTTP Data Collector in theAPI to the Logs Ingestion in theAPI — Microsoft Learn
- Legacy Authentication for Container Insights — Microsoft Learn
- Use customer-managed storage accounts in Azure Monitor Logs — Microsoft Learn
- Azure Monitor HTTP Data Collector API — Microsoft Learn, archived page
- What's New in the " Azure " Monitor Documentation — Microsoft Learn
What an article Can't Know
An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.
You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.
Check what is still true
Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.
Search for a topic in the blogIn the same issue
Three articles on the same topic. The blog has 149 articles, all of which are freely accessible.

