Skip to content

Commit 1edb459

Browse files
author
David Curwin
committed
Onboarding limitations
1 parent a2d6bbf commit 1edb459

File tree

1 file changed

+5
-6
lines changed

1 file changed

+5
-6
lines changed

articles/defender-for-cloud/onboard-machines-with-defender-for-endpoint.md

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ Direct onboarding is a seamless integration between Defender for Endpoint and De
3333

3434
## Enabling direct onboarding
3535

36-
Enabling direct onboarding is an opt-in setting at the tenant level. It affects both existing and new servers onboarded to Defender for Endpoint in the same Microsoft Entra tenant. Shortly after enabling this setting, your server devices will show under the designated subscription. Alerts, software inventory, and vulnerability data are integrated with Defender for Cloud, in a similar way to how it works with Azure VMs.
36+
Enabling direct onboarding is an opt-in setting at the tenant level. It affects both existing and new servers onboarded to Defender for Endpoint in the same Microsoft Entra tenant. Shortly after you enable this setting, your server devices will show under the designated subscription. Alerts, software inventory, and vulnerability data are integrated with Defender for Cloud, in a similar way to how it works with Azure VMs.
3737

3838
Before you begin:
3939

@@ -45,12 +45,12 @@ Before you begin:
4545

4646
1. Go to **Defender for Cloud** > **Environment Settings** > **Direct onboarding**.
4747
1. Switch the **Direct onboarding** toggle to **On**.
48-
1. Select the subscription you would like to use for servers onboarded directly with Defender for Endpoint
48+
1. Select the subscription you would like to use for servers onboarded directly with Defender for Endpoint.
4949
1. Select **Save**.
5050

5151
:::image type="content" source="media/onboard-machines-with-defender-for-endpoint/onboard-with-defender-for-endpoint.png" alt-text="Screenshot of Onboard non-Azure servers with Defender for Endpoint.":::
5252

53-
You've now successfully enabled direct onboarding on your tenant. After you enable it for the first time, it might take up to 24 hours to see your non-Azure servers in your designated subscription.
53+
You now successfully enabled direct onboarding on your tenant. After you enable it for the first time, it might take up to 24 hours to see your non-Azure servers in your designated subscription.
5454

5555
### Deploying Defender for Endpoint on your servers
5656

@@ -60,17 +60,16 @@ Deploying the Defender for Endpoint agent on your on-premises Windows and Linux
6060

6161
- **Plan support**: Direct onboarding provides access to all Defender for Servers Plan 1 features. However, certain features in Plan 2 still require the deployment of the Azure Monitor Agent, which is only available with Azure Arc on non-Azure machines. If you enable Plan 2 on your designated subscription, machines onboarded directly with Defender for Endpoint have access to all Defender for Servers Plan 1 features and the Defender Vulnerability Management Addon features included in Plan 2.
6262
- **Multi-cloud support**: You can directly onboard VMs in AWS and GCP using the Defender for Endpoint agent. However, if you plan to simultaneously connect your AWS or GCP account to Defender for Servers using multicloud connectors, it's currently still recommended to deploy Azure Arc.
63-
- **Simultaneous onboarding limited support**: For servers simultaneously onboarded using multiple methods (for example, direct onboarding combined with Log Analytics workspace-based onboarding), Defender for Cloud makes every effort to correlate them into a single device representation. However, devices using older versions of Defender for Endpoint may face certain limitations. In some instances, this could result in overcharges. We generally advise using the latest agent version. Specifically, for this limitation, ensure your Defender for Endpoint agent versions meet or exceed these minimum versions:
63+
- **Simultaneous onboarding limited support**: For servers simultaneously onboarded using multiple methods (for example, direct onboarding combined with Log Analytics workspace-based onboarding), Defender for Cloud makes every effort to correlate them into a single device representation. However, devices using older versions of Defender for Endpoint might face certain limitations. In some instances, this could result in overcharges. We generally advise using the latest agent version. Specifically, for this limitation, ensure your Defender for Endpoint agent versions meet or exceed these minimum versions:
64+
6465
|Operating System|Minimum agent version|
6566
| -------- | -------- |
6667
|Windows 2019| 10.8555|
6768
|Windows 2012 R2, 2016 (modern, unified agent)|10.8560|
6869
|Linux|30.101.23052.009|
6970

70-
7171
## Next steps
7272

7373
This page showed you how to add your non-Azure machines to Microsoft Defender for Cloud. To monitor their status, use the inventory tools as explained in the following page:
7474

7575
- [Explore and manage your resources with asset inventory](asset-inventory.md)
76-

0 commit comments

Comments
 (0)