Skip to content

Commit 7348f48

Browse files
authored
Merge pull request #287934 from MicrosoftDocs/main
Publish to live, Sunday 4:00PM PDT, 10/06
2 parents 2355e02 + 6828c12 commit 7348f48

File tree

5 files changed

+103
-10
lines changed

5 files changed

+103
-10
lines changed

articles/defender-for-iot/organizations/concept-enterprise.md

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -13,27 +13,22 @@ The number of IoT devices continues to grow exponentially across enterprise netw
1313

1414
While the number of IoT devices continues to grow, they often lack the security safeguards that are common on managed endpoints like laptops and mobile phones. To bad actors, these unmanaged devices can be used as a point of entry for lateral movement or evasion, and too often, the use of such tactics leads to the exfiltration of sensitive information.
1515

16-
[Microsoft Defender for IoT](./index.yml) seamlessly integrates with [Microsoft Defender XDR](/microsoft-365/security/defender) and [Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/) to provide both IoT device discovery and security value for IoT devices, including purpose-built alerts, recommendations, and vulnerability data.
16+
[Microsoft Defender for IoT](./index.yml) seamlessly integrates with [Microsoft Defender XDR](/microsoft-365/security/defender) and [Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/) to provide both IoT device discovery and security value for IoT devices, including purpose-built recommendations, and vulnerability data.
1717

1818
## Enterprise IoT security in Microsoft Defender XDR
1919

20-
Enterprise IoT security in Microsoft Defender XDR provides IoT-specific security value, including alerts, risk and exposure levels, vulnerabilities, and recommendations in Microsoft Defender XDR.
20+
Enterprise IoT security in Microsoft Defender XDR provides IoT-specific security value, including risk and exposure levels, vulnerabilities, and recommendations in Microsoft Defender XDR.
2121

2222
- If you're a Microsoft 365 E5 (ME5)/ E5 Security and Defender for Endpoint P2 customer, [toggle on support](eiot-defender-for-endpoint.md) for **Enterprise IoT Security** in the Microsoft Defender Portal.
2323

2424
- If you don't have ME5/E5 Security licenses, but you're a Microsoft Defender for Endpoint customer, start with a [free trial](billing.md#free-trial) or purchase standalone, per-device licenses to gain the same IoT-specific security value.
2525

2626
:::image type="content" source="media/enterprise-iot/architecture-endpoint-only.png" alt-text="Diagram of the service architecture when you have an Enterprise IoT plan added to Defender for Endpoint." border="false":::
2727

28-
### Alerts
29-
30-
Most Microsoft Defender for Endpoint network-based detections are also relevant for Enterprise IoT devices. For example, network-based detections include alerts for scans involving managed endpoints.
31-
32-
For more information, see [Alerts queue in Microsoft 365 Defender](/microsoft-365/security/defender-endpoint/alerts-queue-endpoint-detection-response).
33-
3428
### Recommendations
3529

3630
The following Defender for Endpoint security recommendations are supported for Enterprise IoT devices:
31+
3732
- **Require authentication for Telnet management interface**
3833
- **Disable insecure administration protocol – Telnet**
3934
- **Remove insecure administration protocols SNMP V1 and SNMP V2**
-9.97 KB
Loading

articles/update-manager/roles-permissions.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: This article explains th roles and permission required to manage Az
44
ms.service: azure-update-manager
55
author: SnehaSudhirG
66
ms.author: sudhirsneha
7-
ms.date: 07/19/2024
7+
ms.date: 10/06/2024
88
ms.topic: overview
99
---
1010

@@ -18,9 +18,10 @@ The built-in roles provide blanket permissions on a virtual machine, which inclu
1818

1919
| **Resource** | **Role** |
2020
|---|---|
21-
| **Azure VM** | Azure Virtual Machine Contributor or Azure [Owner](../role-based-access-control/built-in-roles.md)|
21+
| **Azure VM** | Azure Virtual Machine Contributor or Azure [Owner](../role-based-access-control/built-in-roles/general.md#azure-built-in-roles-for-general).
2222
| **Azure Arc-enabled server** | [Azure Connected Machine Resource Administrator](/azure/azure-arc/servers/security-overview)|
2323

24+
2425
## Permissions
2526

2627
You need the following permissions to manage update operations. The following table shows the permissions that are needed when you use Update Manager. You can create a custom role and assign only the desired permissions to that role so that only permissions for specific actions are provided as per need.

articles/update-manager/support-matrix.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -316,6 +316,7 @@ Europe | North Europe </br> West Europe
316316
France | France Central
317317
Germany | Germany West Central
318318
India | Central India
319+
Italy | Italy North
319320
Japan | Japan East
320321
Korea | Korea Central
321322
Norway | Norway East
Lines changed: 96 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,96 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: azure-monitor
5+
author: rboucher
6+
ms.topic: "include"
7+
ms.date: 10/06/2024
8+
ms.author: robb
9+
ms.custom: "include file"
10+
---
11+
12+
13+
**Data collection volume and retention**
14+
15+
| Pricing tier | Limit per day | Data retention | Comment |
16+
|:---|:---|:---|:---|
17+
| [Pay-as-you-go](../articles/azure-monitor/logs/cost-logs.md#pricing-model)<br>(introduced April 2018) | No limit | Up to 730 days interactive retention/<br> up to 12 years [data archive](../articles/azure-monitor/logs/data-retention-configure.md) | Data retention beyond 31 days is available for extra charges. Learn more about [Azure Monitor pricing](https://azure.microsoft.com/pricing/details/monitor). |
18+
| [Commitment tiers](../articles/azure-monitor/logs/cost-logs.md#commitment-tiers)<br>(introduced November 2019) | No limit | Up to 730 days interactive retention/<br> up to 12 years [data archive](../articles/azure-monitor/logs/data-retention-configure.md) | Data retention beyond 31 days is available for extra charges. Learn more about [Azure Monitor pricing](https://azure.microsoft.com/pricing/details/monitor). |
19+
| [Legacy Per Node (OMS)](../articles/azure-monitor/logs/cost-logs.md#per-node-pricing-tier)<br>(introduced April 2016) | No limit | 30 to 730 days | Data retention beyond 31 days is available for extra charges. Learn more about [Azure Monitor pricing](https://azure.microsoft.com/pricing/details/monitor). Access to use tier is limited to subscriptions that contained a Log Analytics workspace or Application Insights resource on April 2, 2018, or are linked to an Enterprise Agreement that started before February 1, 2019 and is still active. |
20+
| [Legacy Standalone tier](../articles/azure-monitor/logs/cost-logs.md#standalone-pricing-tier)<br>(introduced April 2016) | No limit | 30 to 730 days | Data retention beyond 31 days is available for extra charges. Learn more about [Azure Monitor pricing](https://azure.microsoft.com/pricing/details/monitor). Access to use tier is limited to subscriptions that contained a Log Analytics workspace or Application Insights resource on April 2, 2018, or are linked to an Enterprise Agreement that started before February 1, 2019 and is still active.|
21+
| [Legacy Free tier](../articles/azure-monitor/logs/cost-logs.md#free-trial-pricing-tier)<br>(introduced April 2016) | 500 MB | 7 days | When your workspace reaches the 500-MB-per-day limit, data ingestion stops and resumes at the start of the next day. A day is based on UTC. Data collected by Microsoft Defender for Cloud isn't included in this 500-MB-per-day limit and continues to be collected above this limit. Creating new workspaces in, or moving existing workspaces into, the legacy Free Trial pricing tier is possible only until July 1, 2022. |
22+
| [Legacy Standard tier](../articles/azure-monitor/logs/cost-logs.md#standard-and-premium-pricing-tiers) | No limit | 30 days | Retention can't be adjusted. This tier hasn't been available to any new workspaces since October 1, 2016.|
23+
| [Legacy Premium tier](../articles/azure-monitor/logs/cost-logs.md#standard-and-premium-pricing-tiers) | No limit | 365 days | Retention can't be adjusted. This tier hasn't been available to any new workspaces since October 1, 2016.|
24+
25+
**Number of workspaces per subscription**
26+
27+
| Pricing tier | Workspace limit | Comments
28+
|:---|:---|:---|
29+
| Legacy Free tier | 10 | This limit can't be increased. Creating new workspaces in, or moving existing workspaces into, the legacy Free Trial pricing tier is possible only until July 1, 2022. |
30+
| All other tiers | No limit | You're limited by the number of resources within a resource group and the number of resource groups per subscription. |
31+
32+
<a name="azure-portal"></a>
33+
34+
**Azure portal**
35+
36+
| Category | Limit | Comments |
37+
|:---|:---|:---|
38+
| Maximum records returned by a log query | 30,000 | Reduce results by using query scope, time range, and filters in the query. |
39+
40+
**Data Collector API**
41+
42+
| Category | Limit | Comments |
43+
|:---|:---|:---|
44+
| Maximum size for a single post | 30 MB | Split larger volumes into multiple posts. |
45+
| Maximum size for field values | 32 KB | Fields longer than 32 KB are truncated. |
46+
47+
<a name="la-query-api"></a>
48+
49+
**Query API**
50+
51+
| Category | Limit | Comments |
52+
|:---|:---|:---|
53+
| Maximum records returned in a single query | 500,000 | |
54+
| Maximum size of data returned | ~104 MB (~100 MiB)|The API returns up to 64 MB of compressed data, which translates to up to 100 MB of raw data. |
55+
| Maximum query running time | 10 minutes | See [Timeouts](../articles/azure-monitor/logs/api/timeouts.md) for details.|
56+
| Maximum request rate | 200 requests per 30 seconds per Microsoft Entra user or client IP address | See [Log queries and language](../articles/azure-monitor/service-limits.md#log-queries-and-language).|
57+
58+
**Azure Monitor Logs connector**
59+
60+
| Category | Limit | Comments |
61+
|:---|:---|:---|
62+
| Maximum size of data | ~16.7 MB (~16 MiB) | The connector infrastructure dictates that limit is set lower than query API limit. |
63+
| Maximum number of records | 500,000 | |
64+
| Maximum connector timeout | 110 second | |
65+
| Maximum query timeout | 100 second | |
66+
| Charts | | The Logs page and the connector use different charting libraries for visualization. Some functionality isn't currently available in the connector. |
67+
68+
**Summary rules**
69+
70+
| Category | Limit |
71+
|:---|:---|
72+
| Maximum number of active rules in a workspace | 30 |
73+
| Maximum number of results per bin | 500,000 |
74+
| Maximum results set volume | 100 MB |
75+
| Query time-out for bin processing | 10 minutes |
76+
77+
**General workspace limits**
78+
79+
| Category | Limit | Comments |
80+
|:---|:---|:---|
81+
| Maximum columns in a table | 500 | **AzureDiagnostics** -- columns above the limit are added to the dynamic 'AdditionalFields' column <br> **Custom log created by Data collector API** -- columns above the limit are added to the dynamic 'AdditionalFields' column <br> **Custom log** -- contact support for more |
82+
| Maximum number of custom log tables | 500 | Contact support for more |
83+
| Maximum characters for column name | 45 | |
84+
85+
<b id="data-ingestion-volume-rate">Data ingestion volume rate</b>
86+
87+
Azure Monitor is a high-scale data service that serves thousands of customers sending Terabytes of data daily at a growing pace. To isolate and prevent interruptions in multitenancy service from sudden ingestion bursts, a default ingestion volume rate limit is placed in workspaces and set to 500 MB per minute compressed, which is translated to approximately **6 GB per minute uncompressed**. This limit applies to data ingested from Azure resources via [Diagnostic settings](../articles/azure-monitor/essentials/diagnostic-settings.md). The limit doesn't apply to data ingested from [agents](../articles/azure-monitor/agents/agents-overview.md), or Data Collection Rules.
88+
89+
When the ingested volume rate reaches 80% of the rate limit set in workspace, an event is sent to the `Operation` table in your workspace every 6 hours while the threshold is exceeded. When volume rate limit is reached, a retry mechanism attempts to ingest the data four times in a period of 12 hours and drop it if fails, an event is sent to the `Operation` table in your workspace every 6 hours while the threshold is exceeded.
90+
91+
If your ingestion volume rate continues to exceed threshold or you're expecting to reach it sometime soon, **you can request to increase this limit by opening a support request**.
92+
93+
It's recommended to create an alert to get notified proactively when nearing or reaching ingestion limits. See [Monitor health of Log Analytics workspace in Azure Monitor](../articles/azure-monitor/logs/monitor-workspace.md).
94+
95+
>[!NOTE]
96+
>Depending on how long you've been using Log Analytics, you might have access to legacy pricing tiers. Learn more about [Log Analytics legacy pricing tiers](../articles/azure-monitor/logs/cost-logs.md#legacy-pricing-tiers).

0 commit comments

Comments
 (0)