You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/security-center/security-center-faq.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,7 +21,7 @@ ms.author: v-mohabe
21
21
This FAQ answers questions about Azure Security Center, a service that helps you prevent, detect, and respond to threats with increased visibility into and control over the security of your Microsoft Azure resources.
22
22
23
23
> [!NOTE]
24
-
> Beginning in early June 2017, Security Center will use the Microsoft Monitoring Agent to collect and store data. To learn more, see [Azure Security Center Platform Migration](security-center-platform-migration.md). The information in this article represents Security Center functionality after transition to the Microsoft Monitoring Agent.
24
+
> Security Center uses the Microsoft Monitoring Agent to collect and store data. To learn more, see [Azure Security Center Platform Migration](security-center-platform-migration.md).
25
25
>
26
26
>
27
27
@@ -41,7 +41,7 @@ The **Free tier** provides visibility into the security state of your Azure reso
41
41
The **Standard tier** adds advanced threat detection capabilities, including threat intelligence, behavioral analysis, anomaly detection, security incidents, and threat attribution reports. You can start a Standard tier free trial. To upgrade, select [Pricing Tier](https://docs.microsoft.com/azure/security-center/security-center-pricing) in the security policy. To learn more, see the [pricing page](https://azure.microsoft.com/pricing/details/security-center/).
42
42
43
43
### How can I track who in my organization performed pricing tier changes in Azure Security Center
44
-
As an Azure Subscription may have multiple administrators with permissions to change the pricing tier, a user may wish to know who performed the pricing tier change. To use that, one can use Azure Activity Log. Please see further instructions [here](https://techcommunity.microsoft.com/t5/Security-Identity/Tracking-Changes-in-the-Pricing-Tier-for-Azure-Security-Center/td-p/390832)
44
+
As an Azure Subscription may have multiple administrators with permissions to change the pricing tier, a user may wish to know who performed the pricing tier change. To use that, one can use Azure Activity Log. See further instructions [here](https://techcommunity.microsoft.com/t5/Security-Identity/Tracking-Changes-in-the-Pricing-Tier-for-Azure-Security-Center/td-p/390832)
45
45
46
46
## Permissions
47
47
Azure Security Center uses [Role-Based Access Control (RBAC)](../role-based-access-control/role-assignments-portal.md), which provides [built-in roles](../role-based-access-control/built-in-roles.md) that can be assigned to users, groups, and services in Azure.
@@ -59,7 +59,7 @@ No. Workspaces created by Security Center, while configured for Azure Monitor lo
59
59
-**Free tier** – Security Center enables the 'SecurityCenterFree' solution on the default workspace. You are not billed for the Free tier.
60
60
-**Standard tier** – Security Center enables the 'Security' solution on the default workspace.
61
61
62
-
For more information on pricing, see [Security Center pricing](https://azure.microsoft.com/pricing/details/security-center/). The pricing page addresses changes to security data storage and prorated billing starting in June 2017.
62
+
For more information on pricing, see [Security Center pricing](https://azure.microsoft.com/pricing/details/security-center/).
63
63
64
64
> [!NOTE]
65
65
> The log analytics pricing tier of workspaces created by Security Center does not affect Security Center billing.
@@ -132,7 +132,7 @@ For existing machines on subscriptions onboarded to Security Center before 2019-
132
132
For more information, see the next section [What happens if a SCOM or OMS direct agent is already installed on my VM?](#scomomsinstalled)
133
133
134
134
### What happens if a System Center Operations Manager (SCOM) agent is already installed on my VM?<aname="scomomsinstalled"></a>
135
-
Security center will install the Microsoft Monitoring Agent extension side-by-side to the existing System Center Operations Manager agent. The existing SCOM agent will continue to report to the System Center Operations Manager server normally. Please note that the System Center Operations Manager agent and Microsoft Monitoring Agent share common run-time libraries, which will be updated to the lastest version during this proccess. Note - If System Center Operations Manager agent version 2012 is installed, do not turn automatic provisioning On (manageability capabilities can be lost when the System Center Operations Manager server is also version 2012).
135
+
Security center will install the Microsoft Monitoring Agent extension side-by-side to the existing System Center Operations Manager agent. The existing SCOM agent will continue to report to the System Center Operations Manager server normally. Please note that the System Center Operations Manager agent and Microsoft Monitoring Agent share common run-time libraries, which will be updated to the latest version during this process. Note - If System Center Operations Manager agent version 2012 is installed, do not turn automatic provisioning On (manageability capabilities can be lost when the System Center Operations Manager server is also version 2012).
136
136
137
137
### What is the impact of removing these extensions?
138
138
If you remove the Microsoft Monitoring Extension, Security Center is not able to collect security data from the VM and some security recommendations and alerts are unavailable. Within 24 hours, Security Center determines that the VM is missing the extension and reinstalls the extension.
@@ -157,7 +157,7 @@ You can turn off automatic provisioning for your subscriptions in the security p
157
157
You may want to opt out of automatic provisioning if the following applies to you:
158
158
159
159
- Automatic agent installation by Security Center applies to the entire subscription. You cannot apply automatic installation to a subset of VMs. If there are critical VMs that cannot be installed with the Microsoft Monitoring Agent, then you should opt out of automatic provisioning.
160
-
- Installation of the Microsoft Monitoring Agent (MMA) extension updates the agent’s version. This applies to a direct agent and a SCOM agent (in the latter, the SCOM and MMA share common runtime libraries - which will be updated in the process). If the installed SCOM agent is version 2012 and is upgraded, manageability capabilities can be lost when the SCOM server is also version 2012. You should consider opting out of automatic provisioning if the installed SCOM agent is version 2012.
160
+
- Installation of the Microsoft Monitoring Agent (MMA) extension updates the agent’s version. This applies to a direct agent and a SCOM agent (in the latter, the SCOM and MMA share common runtime libraries - which will be updated in the process). If the installed SCOM agent is version 2012 and is upgraded, manageability capabilities can be lost when the SCOM server is also version 2012. Consider opting out of automatic provisioning if the installed SCOM agent is version 2012.
161
161
- If you have a custom workspace external to the subscription (a centralized workspace) then you should opt out of automatic provisioning. You can manually install the Microsoft Monitoring Agent extension and connect it your workspace without Security Center overriding the connection.
162
162
- If you want to avoid creation of multiple workspaces per subscription and you have your own custom workspace within the subscription, then you have two options:
163
163
@@ -325,7 +325,7 @@ The latency in Security Center scans for vulnerabilities, updates, and issues is
325
325
Security Center typically scans for new data every hour, and refreshes the recommendations accordingly.
326
326
327
327
> [!NOTE]
328
-
> Beginning in early June 2017, Security Center will use the Microsoft Monitoring Agent to collect and store data. To learn more, see [Azure Security Center Platform Migration](security-center-platform-migration.md). The information in this article represents Security Center functionality after transition to the Microsoft Monitoring Agent.
328
+
> Security Center uses the Microsoft Monitoring Agent to collect and store data. To learn more, see [Azure Security Center Platform Migration](security-center-platform-migration.md).
Copy file name to clipboardExpand all lines: articles/security-center/security-center-troubleshooting-guide.md
+8-14Lines changed: 8 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,27 +1,21 @@
1
1
---
2
2
title: Azure Security Center Troubleshooting Guide | Microsoft Docs
3
-
description: This document helps to troubleshoot issues in Azure Security Center.
3
+
description: This document helps troubleshoot issues in Azure Security Center.
4
4
services: security-center
5
-
documentationcenter: na
6
-
author: rkarlin
7
-
manager: barbkess
8
-
editor: ''
5
+
author: memildin
6
+
manager: rkarlin
9
7
10
-
ms.assetid: 44462de6-2cc5-4672-b1d3-dbb4749a28cd
11
8
ms.service: security-center
12
-
ms.devlang: na
13
9
ms.topic: conceptual
14
-
ms.tgt_pltfrm: na
15
-
ms.workload: na
16
-
ms.date: 3/20/2019
17
-
ms.author: rkarlin
10
+
ms.date: 09/10/2019
11
+
ms.author: memildin
18
12
19
13
---
20
14
# Azure Security Center Troubleshooting Guide
21
15
This guide is for information technology (IT) professionals, information security analysts, and cloud administrators whose organizations are using Azure Security Center and need to troubleshoot Security Center related issues.
22
16
23
17
>[!NOTE]
24
-
>Beginning in early June 2017, Security Center uses the Microsoft Monitoring Agent to collect and store data. See [Azure Security Center Platform Migration](security-center-platform-migration.md) to learn more. The information in this article represents Security Center functionality after transition to the Microsoft Monitoring Agent.
18
+
>Security Center uses the Microsoft Monitoring Agent to collect and store data. See [Azure Security Center Platform Migration](security-center-platform-migration.md) to learn more.
25
19
>
26
20
27
21
## Troubleshooting guide
@@ -52,9 +46,9 @@ To see which version of the agent you have, open **Task Manager**, in the **Proc
52
46
## Microsoft Monitoring Agent installation scenarios
53
47
There are two installation scenarios that can produce different results when installing the Microsoft Monitoring Agent on your computer. The supported scenarios are:
54
48
55
-
***Agent installed automatically by Security Center**: in this scenario you will be able to view the alerts in both locations, Security Center and Log search. You will receive e-mail notifications to the email address that was configured in the security policy for the subscription the resource belongs to.
49
+
***Agent installed automatically by Security Center**: in this scenario you will be able to view the alerts in both locations, Security Center and Log search. You will receive email notifications to the email address that was configured in the security policy for the subscription the resource belongs to.
56
50
.
57
-
***Agent manually installed on a VM located in Azure**: in this scenario, if you are using agents downloaded and installed manually prior to February 2017, you will be able to view the alerts in the Security Center portal only if you filter on the subscription the workspace belongs to. In case you filter on the subscription the resource belongs to, you won’t be able to see any alerts. You will receive e-mail notifications to the email address that was configured in the security policy for the subscription the workspace belongs to.
51
+
***Agent manually installed on a VM located in Azure**: in this scenario, if you are using agents downloaded and installed manually prior to February 2017, you can view the alerts in the Security Center portal only if you filter on the subscription the workspace belongs to. If you filter on the subscription the resource belongs to, you won’t see any alerts. You'll receive email notifications to the email address that was configured in the security policy for the subscription the workspace belongs to.
58
52
59
53
>[!NOTE]
60
54
> To avoid the behavior explained in the second scenario, make sure you download the latest version of the agent.
0 commit comments