
Explanation:

The Administering Windows Server Hybrid Core Infrastructure learning path explains that onboarding Windows Server machines to Azure Monitor hinges on a Log Analytics workspace as the data store for logs and metrics, and an agent on the machine to collect and send data. The guide states that "Azure Monitor collects telemetry from Windows Server machines into a Log Analytics workspace," and that for current deployments you should "install the Azure Monitor agent (AMA) on each computer and associate it with a workspace." It further notes that "the AMA replaces the legacy Log Analytics agent" and "uses data collection rules (DCRs) to define which data to collect and to which Log Analytics workspace to send it." Storage accounts, SQL databases, or analytics gateways are not required to onboard a standalone Windows Server to Azure Monitor. Likewise, Device Health Attestation is unrelated to Azure Monitor onboarding.
In short, to monitor an on-premises Windows Server from Azure you create a Log Analytics workspace in the subscription and install the Azure Monitor agent on the server. (In practice, you then configure a DCR to route data from the AMA to the workspace, but no additional Azure resources like SQL or Blob/Azure Files are needed for basic monitoring.)