Skip to content

Commit 8e94e4d

Browse files
Merge pull request #239201 from dcurwin/clarify-billing-may24-2023
Clarify billing
2 parents 3006e76 + f308ea1 commit 8e94e4d

File tree

1 file changed

+17
-16
lines changed

1 file changed

+17
-16
lines changed

articles/defender-for-cloud/plan-defender-for-servers-data-workspace.md

Lines changed: 17 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Review data residency and workspace design for Microsoft Defender f
44
ms.topic: conceptual
55
ms.author: dacurwin
66
author: dcurwin
7-
ms.date: 11/06/2022
7+
ms.date: 05/30/2023
88
ms.custom: references_regions
99
---
1010
# Plan data residency and workspaces for Defender for Servers
@@ -78,13 +78,13 @@ You can store your server information in the default workspace or you can use a
7878

7979
### If I enable Defender for Clouds Servers plan on the subscription level, do I need to enable it on the workspace level?
8080

81-
When you enable the Servers plan on the subscription level, Defender for Cloud will enable the Servers plan on your default workspaces automatically. Connect to the default workspace by selecting **Connect Azure VMs to the default workspace(s) created by Defender for Cloud** option and selecting **Apply**.
81+
When you enable the Servers plan on the subscription level, Defender for Cloud enables the Servers plan on your default workspaces automatically. Connect to the default workspace by selecting **Connect Azure VMs to the default workspace(s) created by Defender for Cloud** option and selecting **Apply**.
8282

8383
:::image type="content" source="media/plan-defender-for-servers-data-workspace/connect-workspace.png" alt-text="Screenshot showing how to auto-provision Defender for Cloud to manage your workspaces.":::
8484

85-
However, if you're using a custom workspace in place of the default workspace, you'll need to enable the Servers plan on all of your custom workspaces that don't have it enabled.
85+
However, if you're using a custom workspace in place of the default workspace, you need to enable the Servers plan on all of your custom workspaces that don't have it enabled.
8686

87-
If you're using a custom workspace and enable the plan on the subscription level only, the `Microsoft Defender for servers should be enabled on workspaces` recommendation will appear on the Recommendations page. This recommendation will give you the option to enable the servers plan on the workspace level with the Fix button. You're charged for all VMs in the subscription even if the Servers plan isn't enabled for the workspace. The VMs won't benefit from features that depend on the Log Analytics workspace, such as Microsoft Defender for Endpoint, VA solution (MDVM/Qualys), and Just-in-Time VM access.
87+
If you're using a custom workspace and enable the plan on the subscription level only, the `Microsoft Defender for servers should be enabled on workspaces` recommendation appears on the Recommendations page. This recommendation gives you the option to enable the servers plan on the workspace level with the Fix button. You're charged for all VMs in the subscription even if the Servers plan isn't enabled for the workspace. The VMs won't benefit from features that depend on the Log Analytics workspace, such as Microsoft Defender for Endpoint, VA solution (MDVM/Qualys), and Just-in-Time VM access.
8888

8989
Enabling the Servers plan on both the subscription and its connected workspaces, won't incur a double charge. The system will identify each unique VM.
9090

@@ -104,11 +104,12 @@ Yes. If you configure your Log Analytics agent to send data to two or more diffe
104104

105105
### Is the 500-MB free data ingestion calculated for an entire workspace or strictly per machine?
106106

107-
You'll get 500-MB free data ingestion per day, for every VM connected to the workspace. Specifically for the [security data types](#what-data-types-are-included-in-the-500-mb-data-daily-allowance) that are directly collected by Defender for Cloud.
107+
You receive a daily allowance of 500 MB of free data ingestion for each virtual machine (VM) connected to the workspace. This allocation specifically applies to the [security data types](#what-data-types-are-included-in-the-500-mb-data-daily-allowance) collected directly by Defender for Cloud.
108108

109-
This data is a daily rate averaged across all nodes. Your total daily free limit is equal to **[number of machines] x 500 MB**. So even if some machines send 100 MB and others send 800 MB, if the total doesn't exceed your total daily free limit, you won't be charged extra.
109+
The data allowance is a daily rate calculated across all connected machines. Your total daily free limit is equal to the **[number of machines] x 500 MB**. So even if on a given day some machines send 100 MB and others send 800 MB, if the total data from all machines doesn't exceed your daily free limit, you won't be charged extra.
110110

111111
### What data types are included in the 500-MB data daily allowance?
112+
112113
Defender for Cloud's billing is closely tied to the billing for Log Analytics. [Microsoft Defender for Servers](defender-for-servers-introduction.md) provides a 500 MB/node/day allocation for machines against the following subset of [security data types](/azure/azure-monitor/reference/tables/tables-category#security):
113114

114115
- [SecurityAlert](/azure/azure-monitor/reference/tables/securityalert)
@@ -129,7 +130,7 @@ You can view your data usage in two different ways, the Azure portal, or by runn
129130

130131
**To view your usage in the Azure portal**:
131132

132-
1. Sign in to the [Azure portal](https://portal.azure.com).
133+
1. Sign in to the [Azure portal](https://portal.azure.com).
133134

134135
1. Navigate to **Log Analytics workspaces**.
135136

@@ -145,7 +146,7 @@ You can also view estimated costs under different pricing tiers by selecting :::
145146

146147
**To view your usage by using a script**:
147148

148-
1. Sign in to the [Azure portal](https://portal.azure.com).
149+
1. Sign in to the [Azure portal](https://portal.azure.com).
149150

150151
1. Navigate to **Log Analytics workspaces** > **Logs**.
151152

@@ -178,7 +179,7 @@ You may want to manage your costs and limit the amount of data collected for a s
178179
> Solution targeting has been deprecated because the Log Analytics agent is being replaced with the Azure Monitor agent and solutions in Azure Monitor are being replaced with insights. You can continue to use solution targeting if you already have it configured, but it is not available in new regions.
179180
> The feature will not be supported after August 31, 2024.
180181
> Regions that support solution targeting until the deprecation date are:
181-
>
182+
>
182183
> | Region code | Region name |
183184
> | :--- | :---------- |
184185
> | CCAN | canadacentral |
@@ -209,13 +210,13 @@ You may want to manage your costs and limit the amount of data collected for a s
209210
>
210211
> | Air-gapped clouds | Region code | Region name |
211212
> | :---- | :---- | :---- |
212-
> | UsNat | EXE | usnateast |
213-
> | UsNat | EXW | usnatwest |
214-
> | UsGov | FF | usgovvirginia |
215-
> | China | MC | ChinaEast2 |
216-
> | UsGov | PHX | usgovarizona |
217-
> | UsSec | RXE | usseceast |
218-
> | UsSec | RXW | ussecwest |
213+
> | UsNat | EXE | usnateast |
214+
> | UsNat | EXW | usnatwest |
215+
> | UsGov | FF | usgovvirginia |
216+
> | China | MC | ChinaEast2 |
217+
> | UsGov | PHX | usgovarizona |
218+
> | UsSec | RXE | usseceast |
219+
> | UsSec | RXW | ussecwest |
219220
220221
## Next steps
221222

0 commit comments

Comments
 (0)