Skip to content

Commit 397990b

Browse files
authored
Merge pull request #197825 from ElazarK/workspace-500mb
added 500mb information
2 parents 04f0c88 + 96e4474 commit 397990b

File tree

6 files changed

+86
-18
lines changed

6 files changed

+86
-18
lines changed

articles/defender-for-cloud/enhanced-security-features-overview.md

Lines changed: 86 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,8 @@
22
title: Understand the enhanced security features of Microsoft Defender for Cloud
33
description: Learn about the benefits of enabling enhanced security in Microsoft Defender for Cloud
44
ms.topic: overview
5-
ms.date: 04/11/2022
6-
ms.author: benmansheim
5+
ms.date: 05/30/2022
76
ms.custom: references_regions
8-
author: bmansheim
97
---
108

119
# Microsoft Defender for Cloud's enhanced security features
@@ -73,18 +71,21 @@ You can use any of the following ways to enable enhanced security for your subsc
7371

7472

7573
### Can I enable Microsoft Defender for Servers on a subset of servers in my subscription?
74+
7675
No. When you enable [Microsoft Defender for Servers](defender-for-servers-introduction.md) on a subscription, all the machines in the subscription will be protected by Defender for Servers.
7776

7877
An alternative is to enable Microsoft Defender for Servers at the Log Analytics workspace level. If you do this, only servers reporting to that workspace will be protected and billed. However, several capabilities will be unavailable. These include Microsoft Defender for Endpoint, VA solution (TVM/Qualys), just-in-time VM access, and more.
7978

8079
### If I already have a license for Microsoft Defender for Endpoint can I get a discount for Defender for Servers?
80+
8181
If you've already got a license for **Microsoft Defender for Endpoint for Servers Plan 2**, you won't have to pay for that part of your Microsoft Defender for Servers license. Learn more about [this license](/microsoft-365/security/defender-endpoint/minimum-requirements#licensing-requirements).
8282

8383
To request your discount, [contact Defender for Cloud's support team](https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/overview). You'll need to provide the relevant workspace ID, region, and number of Microsoft Defender for Endpoint for servers licenses applied for machines in the given workspace.
8484

8585
The discount will be effective starting from the approval date, and won't take place retroactively.
8686

87-
### My subscription has Microsoft Defender for Servers enabled, do I pay for not-running servers?
87+
### My subscription has Microsoft Defender for Servers enabled, do I pay for not-running servers?
88+
8889
No. When you enable [Microsoft Defender for Servers](defender-for-servers-introduction.md) on a subscription, you won't be charged for any machines that are in the deallocated power state while they're in that state. Machines are billed according to their power state as shown in the following table:
8990

9091
| State | Description | Instance usage billed |
@@ -98,35 +99,102 @@ No. When you enable [Microsoft Defender for Servers](defender-for-servers-introd
9899

99100
:::image type="content" source="media/enhanced-security-features-overview/deallocated-virtual-machines.png" alt-text="Azure Virtual Machines showing a deallocated machine.":::
100101

102+
### If I enable Defender for Clouds Servers plan on the Subscription level, do I need to enable it on the workspace level?
103+
104+
When you enable the Servers plan on the subscription level, Defender for Cloud will enable the Servers plan on your default workspace(s) automatically when auto-provisioning is enabled. This can be accomplished on the Auto provisioning page by selecting **Connect Azure VMs to the default workspace(s) created by Defender for Cloud** option and selecting **Apply**.
105+
106+
:::image type="content" source="media/enhanced-security-features-overview/connect-workspace.png" alt-text="Screenshot showing how to auto provision defender for cloud to manage your workspaces.":::
107+
108+
However, if you're using a custom workspace in place of the default workspace, you'll need to enable the Servers plan on all of your custom workspaces that do not have it enabled.
109+
110+
If you're using a custom workspace and enable the plan on the subscription level only, the `Microsoft Defender for servers should be enabled on workspaces` recommendation will appear on the Recommendations page. This recommendation will give you the option to enable the servers plan on the workspace level with the Fix button. Until the workspace has the Servers plan enabled, any connected VM will not benefit from the full security coverage (Microsoft Defender for Endpoint, VA solution (TVM/Qualys), just-in-time VM access, and more) offered by the Defender for Cloud, but will still incur the cost.
111+
112+
Enabling the Servers plan on both the subscription and its connected workspaces, will not incur a double charge. The system will identify each unique VM.
113+
114+
If you enable the Servers plan on cross-subscription workspaces, all connected VMs, even those from subscriptions that it was not enabled on, will be billed.
115+
101116
### Will I be charged for machines without the Log Analytics agent installed?
117+
102118
Yes. When you enable [Microsoft Defender for Servers](defender-for-servers-introduction.md) on a subscription, the machines in that subscription get a range of protections even if you haven't installed the Log Analytics agent. This is applicable for Azure virtual machines, Azure virtual machine scale sets instances, and Azure Arc-enabled servers.
103119

104-
### If a Log Analytics agent reports to multiple workspaces, will I be charged twice?
105-
Yes. If you've configured your Log Analytics agent to send data to two or more different Log Analytics workspaces (multi-homing), you'll be charged for every workspace that has a 'Security' or 'AntiMalware' solution installed.
120+
### If a Log Analytics agent reports to multiple workspaces, will I be charged twice?
121+
122+
No you will not be charged twice.
106123

107124
### If a Log Analytics agent reports to multiple workspaces, is the 500 MB free data ingestion available on all of them?
125+
108126
Yes. If you've configured your Log Analytics agent to send data to two or more different Log Analytics workspaces (multi-homing), you'll get 500 MB free data ingestion. It's calculated per node, per reported workspace, per day, and available for every workspace that has a 'Security' or 'AntiMalware' solution installed. You'll be charged for any data ingested over the 500 MB limit.
109127

110128
### Is the 500 MB free data ingestion calculated for an entire workspace or strictly per machine?
111-
You'll get 500 MB free data ingestion per day, for every machine connected to the workspace. Specifically for security data types directly collected by Defender for Cloud.
112129

113-
This data is a daily rate averaged across all nodes. So even if some machines send 100-MB and others send 800-MB, if the total doesn't exceed the **[number of machines] x 500 MB** free limit, you won't be charged extra.
130+
You'll get 500 MB free data ingestion per day, for every VM connected to the workspace. Specifically for the [security data types](#what-data-types-are-included-in-the-500-mb-data-daily-allowance) that are directly collected by Defender for Cloud.
131+
132+
This data is a daily rate averaged across all nodes. Your total daily free limit is equal to **[number of machines] x 500 MB**. So even if some machines send 100-MB and others send 800-MB, if the total doesn't exceed your total daily free limit, you won't be charged extra.
114133

115134
### What data types are included in the 500 MB data daily allowance?
116135
Defender for Cloud's billing is closely tied to the billing for Log Analytics. [Microsoft Defender for Servers](defender-for-servers-introduction.md) provides a 500 MB/node/day allocation for machines against the following subset of [security data types](/azure/azure-monitor/reference/tables/tables-category#security):
117-
- SecurityAlert
118-
- SecurityBaseline
119-
- SecurityBaselineSummary
120-
- SecurityDetection
121-
- SecurityEvent
122-
- WindowsFirewall
123-
- MaliciousIPCommunication
124-
- SysmonEvent
125-
- ProtectionStatus
126-
- Update and UpdateSummary data types when the Update Management solution is not running on the workspace or solution targeting is enabled
136+
137+
- [SecurityAlert](/azure/azure-monitor/reference/tables/securityalert)
138+
- [SecurityBaseline](/azure/azure-monitor/reference/tables/securitybaseline)
139+
- [SecurityBaselineSummary](/azure/azure-monitor/reference/tables/securitybaselinesummary)
140+
- [SecurityDetection](/azure/azure-monitor/reference/tables/securitydetection)
141+
- [SecurityEvent](/azure/azure-monitor/reference/tables/securityevent)
142+
- [WindowsFirewall](/azure/azure-monitor/reference/tables/windowsfirewall)
143+
- [MaliciousIPCommunication](/azure/azure-monitor/reference/tables/maliciousipcommunication)
144+
- [SysmonEvent](/azure/azure-monitor/reference/tables/sysmonevent)
145+
- [ProtectionStatus](/azure/azure-monitor/reference/tables/protectionstatus)
146+
- [Update](/azure/azure-monitor/reference/tables/update) and [UpdateSummary](/azure/azure-monitor/reference/tables/updatesummary) when the Update Management solution isn't running in the workspace or solution targeting is enabled.
127147

128148
If the workspace is in the legacy Per Node pricing tier, the Defender for Cloud and Log Analytics allocations are combined and applied jointly to all billable ingested data.
129149

150+
## How can I monitor my daily usage
151+
152+
You can view your data usage in two different ways, the Azure portal, or by running a script.
153+
154+
**To view your usage in the Azure portal**:
155+
156+
1. Sign in to the [Azure portal](https://portal.azure.com).
157+
158+
1. Navigate to **Log Analytics workspaces**.
159+
160+
1. Select your workspace.
161+
162+
1. Select **Usage and estimated costs**.
163+
164+
:::image type="content" source="media/enhanced-security-features-overview/data-usage.png" alt-text="Screenshot of your data usage of your log analytics workspace. " lightbox="media/enhanced-security-features-overview/data-usage.png":::
165+
166+
You can also view estimated costs under different pricing tiers by selecting :::image type="icon" source="media/enhanced-security-features-overview/drop-down-icon.png" border="false"::: for each pricing tier.
167+
168+
:::image type="content" source="media/enhanced-security-features-overview/estimated-costs.png" alt-text="Screenshot showing how to view estimated costs under additional pricing tiers." lightbox="media/enhanced-security-features-overview/estimated-costs.png":::
169+
170+
**To view your usage by using a script**:
171+
172+
1. Sign in to the [Azure portal](https://portal.azure.com).
173+
174+
1. Navigate to **Log Analytics workspaces** > **Logs**.
175+
176+
1. Select your time range. Learn about [time ranges](../azure-monitor/logs/log-analytics-tutorial.md).
177+
178+
1. Copy and past the following query into the **Type your query here** section.
179+
180+
```azurecli
181+
let Unit= 'GB';
182+
Usage
183+
| where IsBillable == 'TRUE'
184+
| where DataType in ('SecurityAlert', 'SecurityBaseline', 'SecurityBaselineSummary', 'SecurityDetection', 'SecurityEvent', 'WindowsFirewall', 'MaliciousIPCommunication', 'SysmonEvent', 'ProtectionStatus', 'Update', 'UpdateSummary')
185+
| project TimeGenerated, DataType, Solution, Quantity, QuantityUnit
186+
| summarize DataConsumedPerDataType = sum(Quantity)/1024 by DataType, DataUnit = Unit
187+
| sort by DataConsumedPerDataType desc
188+
```
189+
190+
1. Select **Run**.
191+
192+
:::image type="content" source="media/enhanced-security-features-overview/select-run.png" alt-text="Screenshot showing where to enter your query and where the select run button is located." lightbox="media/enhanced-security-features-overview/select-run.png":::
193+
194+
You can learn how to [Analyze usage in Log Analytics workspace](../azure-monitor/logs/analyze-usage.md).
195+
196+
Based on your usage, you won't be billed until you've used your daily allowance. If you're receiving a bill, it's only for the data used after the 500mb has been consumed, or for other service that does not fall under the coverage of Defender for Cloud.
197+
130198
## Next steps
131199
This article explained Defender for Cloud's pricing options. For related material, see:
132200
204 KB
Loading
149 KB
Loading
233 Bytes
Loading
233 KB
Loading
129 KB
Loading

0 commit comments

Comments
 (0)