Skip to content

Commit 472f3c8

Browse files
Merge pull request #216494 from rayne-wiselman/rayne-october31
adding plan defender for servers article
2 parents e85e822 + ec4cc39 commit 472f3c8

11 files changed

+602
-26
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -166,6 +166,24 @@
166166
- name: Reference list of attack paths and cloud security graph components
167167
displayName: attack, paths, security, graph, components
168168
href: attack-path-reference.md
169+
- name: Protect servers
170+
items:
171+
- name: Plan Defender for Servers deployment
172+
items:
173+
- name: Get started
174+
href: plan-defender-for-servers.md
175+
- name: Review data residency, workspace design
176+
href: plan-defender-for-servers-data-workspace.md
177+
- name: Determine roles and access
178+
href: plan-defender-for-servers-roles.md
179+
- name: Select a plan
180+
href: plan-defender-for-servers-select-plan.md
181+
- name: Review agents and extensions
182+
href: plan-defender-for-servers-agents.md
183+
- name: Scale Defender for Servers deployment
184+
href: plan-defender-for-servers-scale.md
185+
- name: Common questions
186+
href: faq-defender-for-servers.yml
169187
- name: Protect cloud workloads
170188
items:
171189
- name: Agentless scanning

articles/defender-for-cloud/enhanced-security-features-overview.md

Lines changed: 32 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -6,32 +6,38 @@ ms.date: 07/21/2022
66
ms.custom: references_regions, ignite-2022
77
---
88

9-
# Microsoft Defender for Cloud's basic and enhanced security features
10-
11-
Defender for Cloud offers many enhanced security features that can help protect your organization against threats and attacks.
12-
13-
- **Basic security features** (Free) - When you open Defender for Cloud in the Azure portal for the first time or if you enable it through the API, Defender for Cloud is enabled for free on all your Azure subscriptions. By default, Defender for Cloud provides the [secure score](secure-score-security-controls.md), [security policy and basic recommendations](security-policy-concept.md), and [network security assessment](protect-network-resources.md) to help you protect your Azure resources.
14-
15-
If you want to try out the enhanced security features, [enable enhanced security features](enable-enhanced-security.md) for free for the first 30 days. At the end of 30 days, if you decide to continue using the service, we'll automatically start charging for usage. For pricing details in your local currency or region, see the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/).
16-
17-
- **Enhanced security features** (Paid) - When you enable the enhanced security features, Defender for Cloud can provide unified security management and threat protection across your hybrid cloud workloads, including:
18-
19-
- **Microsoft Defender for Endpoint** - Microsoft Defender for Servers includes [Microsoft Defender for Endpoint](https://www.microsoft.com/microsoft-365/security/endpoint-defender) for comprehensive endpoint detection and response (EDR). Learn more about the benefits of using Microsoft Defender for Endpoint together with Defender for Cloud in [Use Defender for Cloud's integrated EDR solution](integration-defender-for-endpoint.md).
20-
- **Vulnerability assessment for virtual machines, container registries, and SQL resources** - Easily enable vulnerability assessment solutions to discover, manage, and resolve vulnerabilities. View, investigate, and remediate the findings directly from within Defender for Cloud.
21-
- **Multicloud security** - Connect your accounts from Amazon Web Services (AWS) and Google Cloud Platform (GCP) to protect resources and workloads on those platforms with a range of Microsoft Defender for Cloud security features.
22-
- **Hybrid security** – Get a unified view of security across all of your on-premises and cloud workloads. Apply security policies and continuously assess the security of your hybrid cloud workloads to ensure compliance with security standards. Collect, search, and analyze security data from multiple sources, including firewalls and other partner solutions.
23-
- **Threat protection alerts** - Advanced behavioral analytics and the Microsoft Intelligent Security Graph provide an edge over evolving cyber-attacks. Built-in behavioral analytics and machine learning can identify attacks and zero-day exploits. Monitor networks, machines, data stores (SQL servers hosted inside and outside Azure, Azure SQL databases, Azure SQL Managed Instance, and Azure Storage) and cloud services for incoming attacks and post-breach activity. Streamline investigation with interactive tools and contextual threat intelligence.
24-
- **Track compliance with a range of standards** - Defender for Cloud continuously assesses your hybrid cloud environment to analyze the risk factors according to the controls and best practices in [Microsoft cloud security benchmark](/security/benchmark/azure/introduction). When you enable the enhanced security features, you can apply a range of other industry standards, regulatory standards, and benchmarks according to your organization's needs. Add standards and track your compliance with them from the [regulatory compliance dashboard](update-regulatory-compliance-packages.md).
25-
- **Access and application controls** - Block malware and other unwanted applications by applying machine learning powered recommendations adapted to your specific workloads to create allowlists and blocklists. Reduce the network attack surface with just-in-time, controlled access to management ports on Azure VMs. Access and application control drastically reduce exposure to brute force and other network attacks.
26-
- **Container security features** - Benefit from vulnerability management and real-time threat protection on your containerized environments. Charges are based on the number of unique container images pushed to your connected registry. After an image has been scanned once, you won't be charged for it again unless it's modified and pushed once more.
27-
- **Breadth threat protection for resources connected to Azure** - Cloud-native threat protection for the Azure services common to all of your resources: Azure Resource Manager, Azure DNS, Azure network layer, and Azure Key Vault. Defender for Cloud has unique visibility into the Azure management layer and the Azure DNS layer, and can therefore protect cloud resources that are connected to those layers.
28-
- **Manage your Cloud Security Posture Management (CSPM)** - CSPM offers you the ability to remediate security issues and review your security posture through the tools provided. These tools include:
29-
- Security governance and regulatory compliance
30-
- Cloud security graph
31-
- Attack path analysis
32-
- Agentless scanning for machines
9+
# Basic and enhanced security features
10+
11+
Defender for Cloud offers basic, and many enhanced security features that can help protect your organization against threats and attacks.
12+
13+
## Basic features
14+
15+
When you open Defender for Cloud in the Azure portal for the first time or if you enable it through the API, Defender for Cloud is enabled for free on all your Azure subscriptions. By default, Defender for Cloud provides foundational cloud security and posture management (CSPM) features, including [secure score](secure-score-security-controls.md), [security policy and basic recommendations](security-policy-concept.md), and [network security assessment](protect-network-resources.md) to help you protect your Azure resources.
16+
17+
## Try out enhanced features
18+
19+
If you want to try out the enhanced security features, [enable enhanced security features](enable-enhanced-security.md) for free for the first 30 days. At the end of 30 days, if you decide to continue using the service, we'll automatically start charging for usage. For pricing details in your local currency or region, see the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/).
20+
21+
## Enhanced features
22+
23+
When you enable the enhanced security features (paid), Defender for Cloud can provide unified security management and threat protection across your hybrid cloud workloads, including:
24+
25+
- **Microsoft Defender for Endpoint** - Microsoft Defender for Servers includes [Microsoft Defender for Endpoint](https://www.microsoft.com/microsoft-365/security/endpoint-defender) for comprehensive endpoint detection and response (EDR). Learn more about the benefits of using Microsoft Defender for Endpoint together with Defender for Cloud in [Use Defender for Cloud's integrated EDR solution](integration-defender-for-endpoint.md).
26+
- **Vulnerability assessment for virtual machines, container registries, and SQL resources** - Easily enable vulnerability assessment solutions to discover, manage, and resolve vulnerabilities. View, investigate, and remediate the findings directly from within Defender for Cloud.
27+
- **Multicloud security** - Connect your accounts from Amazon Web Services (AWS) and Google Cloud Platform (GCP) to protect resources and workloads on those platforms with a range of Microsoft Defender for Cloud security features.
28+
- **Hybrid security** – Get a unified view of security across all of your on-premises and cloud workloads. Apply security policies and continuously assess the security of your hybrid cloud workloads to ensure compliance with security standards. Collect, search, and analyze security data from multiple sources, including firewalls and other partner solutions.
29+
- **Threat protection alerts** - Advanced behavioral analytics and the Microsoft Intelligent Security Graph provide an edge over evolving cyber-attacks. Built-in behavioral analytics and machine learning can identify attacks and zero-day exploits. Monitor networks, machines, data stores (SQL servers hosted inside and outside Azure, Azure SQL databases, Azure SQL Managed Instance, and Azure Storage) and cloud services for incoming attacks and post-breach activity. Streamline investigation with interactive tools and contextual threat intelligence.
30+
- **Track compliance with a range of standards** - Defender for Cloud continuously assesses your hybrid cloud environment to analyze the risk factors according to the controls and best practices in [Microsoft cloud security benchmark](/security/benchmark/azure/introduction). When you enable the enhanced security features, you can apply a range of other industry standards, regulatory standards, and benchmarks according to your organization's needs. Add standards and track your compliance with them from the [regulatory compliance dashboard](update-regulatory-compliance-packages.md).
31+
- **Access and application controls** - Block malware and other unwanted applications by applying machine learning powered recommendations adapted to your specific workloads to create allowlists and blocklists. Reduce the network attack surface with just-in-time, controlled access to management ports on Azure VMs. Access and application control drastically reduce exposure to brute force and other network attacks.
32+
- **Container security features** - Benefit from vulnerability management and real-time threat protection on your containerized environments. Charges are based on the number of unique container images pushed to your connected registry. After an image has been scanned once, you won't be charged for it again unless it's modified and pushed once more.
33+
- **Breadth threat protection for resources connected to Azure** - Cloud-native threat protection for the Azure services common to all of your resources: Azure Resource Manager, Azure DNS, Azure network layer, and Azure Key Vault. Defender for Cloud has unique visibility into the Azure management layer and the Azure DNS layer, and can therefore protect cloud resources that are connected to those layers.
34+
- **Manage your Cloud Security Posture Management (CSPM)** - CSPM offers you the ability to remediate security issues and review your security posture through the tools provided. These tools include:
35+
- Security governance and regulatory compliance
36+
- Cloud security graph
37+
- Attack path analysis
38+
- Agentless scanning for machines
39+
3340

34-
Learn more about [CSPM](concept-cloud-security-posture-management.md).
3541

3642
## FAQ - Pricing and billing
3743

@@ -149,7 +155,7 @@ Defender for Cloud's billing is closely tied to the billing for Log Analytics. [
149155

150156
If the workspace is in the legacy Per Node pricing tier, the Defender for Cloud and Log Analytics allocations are combined and applied jointly to all billable ingested data.
151157

152-
### How can I monitor my daily usage
158+
## How can I monitor my daily usage?
153159

154160
You can view your data usage in two different ways, the Azure portal, or by running a script.
155161

Lines changed: 109 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
1+
### YamlMime:FAQ
2+
metadata:
3+
title: FAQ — Microsoft Defender for Servers
4+
description: This article provides answers to common questions about Microsoft Defender for Servers.
5+
ms.topic: faq
6+
ms.service: defender-for-cloud
7+
author: bmansheim
8+
ms.author: benmansheim
9+
ms.date: 11/29/2022
10+
title: Frequently asked questions – Defender for Servers
11+
summary: This article answers common questions about Microsoft Defender for Servers.
12+
13+
14+
sections:
15+
- name: Ignored
16+
questions:
17+
- question: |
18+
Can I enable on a subset of machines in a subscription?
19+
answer: |
20+
No. When you enable Microsoft Defender for Servers on an Azure subscription or a connected AWS account/GCP project, all of the connected machines are protected by Defender for Servers. This includes servers that don't have the Log Analytics/Azure Monitor agent installed.
21+
22+
- question: |
23+
Can I get a discount if I already have Microsoft Defender for Endpoint license?
24+
answer: |
25+
If you already have a license for Microsoft Defender for Endpoint for Servers, you won't have to pay for that part of your Microsoft Defender for Servers Plan 2 license.
26+
27+
To request your discount, contact Defender for Cloud's support team via the portal.
28+
29+
- You'll need to provide the relevant workspace ID, region, and number of Defender for Endpoint for servers licenses applied for machines in the given workspace.
30+
- The discount will be effective starting from the approval date, and won't take place retroactively.
31+
32+
- question: |
33+
What servers do I pay for in a subscription?
34+
answer: |
35+
When you enable Defender for Servers on a subscription, you're charged for all machines, in accordance with their power state.
36+
37+
**Azure VMs:**
38+
39+
State | Details | Billing
40+
--- | --- | ---
41+
Starting | VM starting up | Not billed
42+
Running | Normal working state | Billed
43+
Stopping | Transitional, will move to Stopped state when complete. | Billed
44+
Stopped | VM shut down from within guest OS or using PowerOff APIs. Hardware is still allocated and the machine remains on the host. | Billed
45+
Deallocating | Transitional, will move to Deallocated state when complete. | Not billed
46+
Deallocated | VM stopped and removed from the host. | Not billed
47+
48+
**Azure Arc machines:**
49+
50+
**State** | **Details* | **Billing**
51+
--- | --- | ---
52+
Connecting | Servers connected but heartbeat not yet received | Not billed
53+
Connected | Receiving regular heartbeat from Connected Machine agent | Billed
54+
Offline/Disconnected | No heartbeat received with 15-30 minutes | Not billed
55+
Expired | If disconnected for 45 days status can change to Expired. | Not billed
56+
57+
58+
- question: |
59+
Do I need to enable on the subscription and workspace?
60+
answer: |
61+
When you enable the Servers plan on the subscription level, Defender for Cloud automatically enables the plan on your default workspaces automatically. If you're using a custom workspace, you need to select it to enable the plan. Note that:
62+
63+
- If you turn on Defender for Servers for a subscription and for a connected custom workspace, you aren't charged for both. The system identifies unique VMs.
64+
- If you enable Defender for Servers on cross-subscription workspaces:
65+
- For the Log Analytics agent, connected machines from all subscriptions are billed, including subscriptions that don't have the servers plan enabled.
66+
- For the Azure Monitor agent, billing and feature coverage for Defender for Servers depends only on the plan being enabled in the subscription.
67+
68+
69+
- question: |
70+
Is the free allowance per workspace or per machine?
71+
answer: |
72+
You get 500-MB free data ingestion per day, for every VM connected to the workspace. This is specifically for the security data types that are directly collected by Defender for Cloud.
73+
74+
This data is a daily rate averaged across all nodes. Your total daily free limit is equal to [number of machines] x 500 MB. So even if some machines send 100 MB and others send 800 MB, if the total doesn't exceed your total daily free limit, you won't be charged extra.
75+
76+
- question: |
77+
What data types are included in the daily allowance?
78+
answer: |
79+
Defender for Cloud's billing is closely tied to the billing for Log Analytics. [Microsoft Defender for Servers](defender-for-servers-introduction.md) provides a 500 MB/node/day allocation for machines against the following subset of [security data types](/azure/azure-monitor/reference/tables/tables-category#security):
80+
81+
- [SecurityAlert](/azure/azure-monitor/reference/tables/securityalert)
82+
- [SecurityBaseline](/azure/azure-monitor/reference/tables/securitybaseline)
83+
- [SecurityBaselineSummary](/azure/azure-monitor/reference/tables/securitybaselinesummary)
84+
- [SecurityDetection](/azure/azure-monitor/reference/tables/securitydetection)
85+
- [SecurityEvent](/azure/azure-monitor/reference/tables/securityevent)
86+
- [WindowsFirewall](/azure/azure-monitor/reference/tables/windowsfirewall)
87+
- [SysmonEvent](/azure/azure-monitor/reference/tables/sysmonevent)
88+
- [ProtectionStatus](/azure/azure-monitor/reference/tables/protectionstatus)
89+
- [Update](/azure/azure-monitor/reference/tables/update) and [UpdateSummary](/azure/azure-monitor/reference/tables/updatesummary) when the Update Management solution isn't running in the workspace or solution targeting is enabled.
90+
91+
If the workspace is in the legacy Per Node pricing tier, the Defender for Cloud and Log Analytics allocations are combined and applied jointly to all billable ingested data.
92+
93+
- question: |
94+
Am I charged for machines without Log Analytics installed?
95+
answer: |
96+
Yes. When you enable Microsoft Defender for Servers on an Azure subscription or a connected AWS/GCP account/project, you'll be charged for all machines that are connected to your Azure subscription or AWS account. The term machines include Azure virtual machines, Azure Virtual Machine Scale Sets instances, and Azure Arc-enabled servers. Machines that don't have Log Analytics installed are covered by protections that don't depend on the Log Analytics agent.
97+
98+
- question: |
99+
If an agent reports to multiple workspaces, am I charged twice?
100+
answer: |
101+
If a machine, reports to multiple workspaces, and all of them have Defender for Servers enabled, the machines will be billed for each attached workspace.
102+
103+
104+
105+
additionalContent: |
106+
107+
## Next steps
108+
109+
[Plan your Defender for Servers deployment](./plan-defender-for-servers.md)
189 KB
Loading
190 KB
Loading

0 commit comments

Comments
 (0)