[ARC 3.1] Build Sheet: A Machine Configuration Baseline

Take a built-in baseline from audit to enforcement: make the drift-visibility decision, remediate machines already adrift, check the meter, and prove it with a deliberately broken setting.
Azure Arc for servers: extending the Azure management plane to servers beyond the domain.

Take a built-in baseline from audit to enforcement: make the drift-visibility decision, remediate machines already adrift, check the meter, and prove it with a deliberately broken setting.

Machine configuration is the closest thing the cloud has to a GPO. It genuinely enforces state, but it is machine-scope only, it lags, one mode costs you the drift interval, and it meters. Here is where the analogy stops.

The build companion to the onboarding article: the low-power onboarding identity, the connectivity choice, agent hardening, and the verification that proves a server is genuinely managed.

Onboarding a server to Arc looks like an install step. It is really a grant of code execution and a network-path decision, and the defaults do not make either choice for you.

Arc extends Azure’s management plane onto servers Azure does not host. The control plane is free, the management meters, and your Windows Server licensing decides which.