You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/enhanced-security-features-overview.md
+86-18Lines changed: 86 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,10 +2,8 @@
2
2
title: Understand the enhanced security features of Microsoft Defender for Cloud
3
3
description: Learn about the benefits of enabling enhanced security in Microsoft Defender for Cloud
4
4
ms.topic: overview
5
-
ms.date: 04/11/2022
6
-
ms.author: benmansheim
5
+
ms.date: 05/30/2022
7
6
ms.custom: references_regions
8
-
author: bmansheim
9
7
---
10
8
11
9
# Microsoft Defender for Cloud's enhanced security features
@@ -73,18 +71,21 @@ You can use any of the following ways to enable enhanced security for your subsc
73
71
74
72
75
73
### Can I enable Microsoft Defender for Servers on a subset of servers in my subscription?
74
+
76
75
No. When you enable [Microsoft Defender for Servers](defender-for-servers-introduction.md) on a subscription, all the machines in the subscription will be protected by Defender for Servers.
77
76
78
77
An alternative is to enable Microsoft Defender for Servers at the Log Analytics workspace level. If you do this, only servers reporting to that workspace will be protected and billed. However, several capabilities will be unavailable. These include Microsoft Defender for Endpoint, VA solution (TVM/Qualys), just-in-time VM access, and more.
79
78
80
79
### If I already have a license for Microsoft Defender for Endpoint can I get a discount for Defender for Servers?
80
+
81
81
If you've already got a license for **Microsoft Defender for Endpoint for Servers Plan 2**, you won't have to pay for that part of your Microsoft Defender for Servers license. Learn more about [this license](/microsoft-365/security/defender-endpoint/minimum-requirements#licensing-requirements).
82
82
83
83
To request your discount, [contact Defender for Cloud's support team](https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/overview). You'll need to provide the relevant workspace ID, region, and number of Microsoft Defender for Endpoint for servers licenses applied for machines in the given workspace.
84
84
85
85
The discount will be effective starting from the approval date, and won't take place retroactively.
86
86
87
-
### My subscription has Microsoft Defender for Servers enabled, do I pay for not-running servers?
87
+
### My subscription has Microsoft Defender for Servers enabled, do I pay for not-running servers?
88
+
88
89
No. When you enable [Microsoft Defender for Servers](defender-for-servers-introduction.md) on a subscription, you won't be charged for any machines that are in the deallocated power state while they're in that state. Machines are billed according to their power state as shown in the following table:
89
90
90
91
| State | Description | Instance usage billed |
@@ -98,35 +99,102 @@ No. When you enable [Microsoft Defender for Servers](defender-for-servers-introd
98
99
99
100
:::image type="content" source="media/enhanced-security-features-overview/deallocated-virtual-machines.png" alt-text="Azure Virtual Machines showing a deallocated machine.":::
100
101
102
+
### If I enable Defender for Clouds Servers plan on the Subscription level, do I need to enable it on the workspace level?
103
+
104
+
When you enable the Servers plan on the subscription level, Defender for Cloud will enable the Servers plan on your default workspace(s) automatically when auto-provisioning is enabled. This can be accomplished on the Auto provisioning page by selecting **Connect Azure VMs to the default workspace(s) created by Defender for Cloud** option and selecting **Apply**.
105
+
106
+
:::image type="content" source="media/enhanced-security-features-overview/connect-workspace.png" alt-text="Screenshot showing how to auto provision defender for cloud to manage your workspaces.":::
107
+
108
+
However, if you're using a custom workspace in place of the default workspace, you'll need to enable the Servers plan on all of your custom workspaces that do not have it enabled.
109
+
110
+
If you're using a custom workspace and enable the plan on the subscription level only, the `Microsoft Defender for servers should be enabled on workspaces` recommendation will appear on the Recommendations page. This recommendation will give you the option to enable the servers plan on the workspace level with the Fix button. Until the workspace has the Servers plan enabled, any connected VM will not benefit from the full security coverage (Microsoft Defender for Endpoint, VA solution (TVM/Qualys), just-in-time VM access, and more) offered by the Defender for Cloud, but will still incur the cost.
111
+
112
+
Enabling the Servers plan on both the subscription and its connected workspaces, will not incur a double charge. The system will identify each unique VM.
113
+
114
+
If you enable the Servers plan on cross-subscription workspaces, all connected VMs, even those from subscriptions that it was not enabled on, will be billed.
115
+
101
116
### Will I be charged for machines without the Log Analytics agent installed?
117
+
102
118
Yes. When you enable [Microsoft Defender for Servers](defender-for-servers-introduction.md) on a subscription, the machines in that subscription get a range of protections even if you haven't installed the Log Analytics agent. This is applicable for Azure virtual machines, Azure virtual machine scale sets instances, and Azure Arc-enabled servers.
103
119
104
-
### If a Log Analytics agent reports to multiple workspaces, will I be charged twice?
105
-
Yes. If you've configured your Log Analytics agent to send data to two or more different Log Analytics workspaces (multi-homing), you'll be charged for every workspace that has a 'Security' or 'AntiMalware' solution installed.
120
+
### If a Log Analytics agent reports to multiple workspaces, will I be charged twice?
121
+
122
+
No you will not be charged twice.
106
123
107
124
### If a Log Analytics agent reports to multiple workspaces, is the 500 MB free data ingestion available on all of them?
125
+
108
126
Yes. If you've configured your Log Analytics agent to send data to two or more different Log Analytics workspaces (multi-homing), you'll get 500 MB free data ingestion. It's calculated per node, per reported workspace, per day, and available for every workspace that has a 'Security' or 'AntiMalware' solution installed. You'll be charged for any data ingested over the 500 MB limit.
109
127
110
128
### Is the 500 MB free data ingestion calculated for an entire workspace or strictly per machine?
111
-
You'll get 500 MB free data ingestion per day, for every machine connected to the workspace. Specifically for security data types directly collected by Defender for Cloud.
112
129
113
-
This data is a daily rate averaged across all nodes. So even if some machines send 100-MB and others send 800-MB, if the total doesn't exceed the **[number of machines] x 500 MB** free limit, you won't be charged extra.
130
+
You'll get 500 MB free data ingestion per day, for every VM connected to the workspace. Specifically for the [security data types](#what-data-types-are-included-in-the-500-mb-data-daily-allowance) that are directly collected by Defender for Cloud.
131
+
132
+
This data is a daily rate averaged across all nodes. Your total daily free limit is equal to **[number of machines] x 500 MB**. So even if some machines send 100-MB and others send 800-MB, if the total doesn't exceed your total daily free limit, you won't be charged extra.
114
133
115
134
### What data types are included in the 500 MB data daily allowance?
116
135
Defender for Cloud's billing is closely tied to the billing for Log Analytics. [Microsoft Defender for Servers](defender-for-servers-introduction.md) provides a 500 MB/node/day allocation for machines against the following subset of [security data types](/azure/azure-monitor/reference/tables/tables-category#security):
117
-
- SecurityAlert
118
-
- SecurityBaseline
119
-
- SecurityBaselineSummary
120
-
- SecurityDetection
121
-
- SecurityEvent
122
-
- WindowsFirewall
123
-
- MaliciousIPCommunication
124
-
- SysmonEvent
125
-
- ProtectionStatus
126
-
- Update and UpdateSummary data types when the Update Management solution is not running on the workspace or solution targeting is enabled
-[Update](/azure/azure-monitor/reference/tables/update) and [UpdateSummary](/azure/azure-monitor/reference/tables/updatesummary) when the Update Management solution isn't running in the workspace or solution targeting is enabled.
127
147
128
148
If the workspace is in the legacy Per Node pricing tier, the Defender for Cloud and Log Analytics allocations are combined and applied jointly to all billable ingested data.
129
149
150
+
## How can I monitor my daily usage
151
+
152
+
You can view your data usage in two different ways, the Azure portal, or by running a script.
153
+
154
+
**To view your usage in the Azure portal**:
155
+
156
+
1. Sign in to the [Azure portal](https://portal.azure.com).
157
+
158
+
1. Navigate to **Log Analytics workspaces**.
159
+
160
+
1. Select your workspace.
161
+
162
+
1. Select **Usage and estimated costs**.
163
+
164
+
:::image type="content" source="media/enhanced-security-features-overview/data-usage.png" alt-text="Screenshot of your data usage of your log analytics workspace. " lightbox="media/enhanced-security-features-overview/data-usage.png":::
165
+
166
+
You can also view estimated costs under different pricing tiers by selecting :::image type="icon" source="media/enhanced-security-features-overview/drop-down-icon.png" border="false"::: for each pricing tier.
167
+
168
+
:::image type="content" source="media/enhanced-security-features-overview/estimated-costs.png" alt-text="Screenshot showing how to view estimated costs under additional pricing tiers." lightbox="media/enhanced-security-features-overview/estimated-costs.png":::
169
+
170
+
**To view your usage by using a script**:
171
+
172
+
1. Sign in to the [Azure portal](https://portal.azure.com).
173
+
174
+
1. Navigate to **Log Analytics workspaces** > **Logs**.
175
+
176
+
1. Select your time range. Learn about [time ranges](../azure-monitor/logs/log-analytics-tutorial.md).
177
+
178
+
1. Copy and past the following query into the **Type your query here** section.
179
+
180
+
```azurecli
181
+
let Unit= 'GB';
182
+
Usage
183
+
| where IsBillable == 'TRUE'
184
+
| where DataType in ('SecurityAlert', 'SecurityBaseline', 'SecurityBaselineSummary', 'SecurityDetection', 'SecurityEvent', 'WindowsFirewall', 'MaliciousIPCommunication', 'SysmonEvent', 'ProtectionStatus', 'Update', 'UpdateSummary')
| summarize DataConsumedPerDataType = sum(Quantity)/1024 by DataType, DataUnit = Unit
187
+
| sort by DataConsumedPerDataType desc
188
+
```
189
+
190
+
1. Select **Run**.
191
+
192
+
:::image type="content" source="media/enhanced-security-features-overview/select-run.png" alt-text="Screenshot showing where to enter your query and where the select run button is located." lightbox="media/enhanced-security-features-overview/select-run.png":::
193
+
194
+
You can learn how to [Analyze usage in Log Analytics workspace](../azure-monitor/logs/analyze-usage.md).
195
+
196
+
Based on your usage, you won't be billed until you've used your daily allowance. If you're receiving a bill, it's only for the data used after the 500mb has been consumed, or for other service that does not fall under the coverage of Defender for Cloud.
197
+
130
198
## Next steps
131
199
This article explained Defender for Cloud's pricing options. For related material, see:
0 commit comments