Thinking it through further, to be useful...
I need to be able to set a config that will work on ANY machine. Unlike "secure by default", where we only want to install services we need, in monitoring, we want MPCM to monitor EVERYTHING that's installed, and ignore anything that's not. Is that how MPCM works? For example, if I enable IIS monitoring on a machine where IIS is not installed, do bad things happen?
In particular, I notice unique IDs for network connections and hard disks. Those sure won't be usable globally. Don't know what all the possible ramifications are of this, but it sounds like settings that monitor "All Adapters" and "All Disks", with per-machine exceptions, would make a lot of sense.