Skip to content

Commit ef847f9

Browse files
authored
Merge pull request #223275 from ktoliver/2019138
edit pass: Defender for Servers set of articles
2 parents 1e7a125 + 1d2c7ff commit ef847f9

9 files changed

+263
-251
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
expanded: true
66
items:
77
- name: What is Microsoft Defender for Cloud?
8-
displayName: Defender for cloud, servers, storage, sql, containers, app service, key vaulkt, resource manager, dns, open-source relational databases, Azure cosmos db, db, Azure, defender
8+
displayName: Defender for cloud, servers, storage, sql, containers, app service, key vault, resource manager, dns, open-source relational databases, Azure cosmos db, db, Azure, defender
99
href: defender-for-cloud-introduction.md
1010
- name: What are the enhanced security features?
1111
displayName: azure defender
@@ -170,15 +170,15 @@
170170
- name: Get started
171171
displayName: VM, JIT, plan 1, plan 2, plans, vulnerability assessment, threat management, defender for endpoint, vulnerability scanner, Qualys, FIM, File integrity monitoring, adaptive application controls, adaptive network hardening, docker, fileless attack detection, auditd, simulate alerts
172172
href: plan-defender-for-servers.md
173-
- name: Review data residency, workspace design
173+
- name: Review data residency and workspace design
174174
href: plan-defender-for-servers-data-workspace.md
175175
- name: Determine roles and access
176176
href: plan-defender-for-servers-roles.md
177177
- name: Select a plan
178178
href: plan-defender-for-servers-select-plan.md
179179
- name: Review agents and extensions
180180
href: plan-defender-for-servers-agents.md
181-
- name: Scale Defender for Servers deployment
181+
- name: Scale a Defender for Servers deployment
182182
href: plan-defender-for-servers-scale.md
183183
- name: Common questions
184184
href: faq-defender-for-servers.yml

articles/defender-for-cloud/faq-defender-for-servers.yml

Lines changed: 33 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -1,82 +1,82 @@
11
### YamlMime:FAQ
22
metadata:
3-
title: FAQ Microsoft Defender for Servers
4-
description: This article provides answers to common questions about Microsoft Defender for Servers.
3+
title: FAQ for Microsoft Defender for Servers
4+
description: Get answers to common questions about Microsoft Defender for Servers.
55
ms.topic: faq
66
ms.service: defender-for-cloud
77
author: bmansheim
88
ms.author: benmansheim
99
ms.date: 11/29/2022
10-
title: Frequently asked questions Defender for Servers
11-
summary: This article answers common questions about Microsoft Defender for Servers.
10+
title: Frequently asked questions for Defender for Servers
11+
summary: Get answers to common questions about Microsoft Defender for Servers.
1212

1313

1414
sections:
1515
- name: Ignored
1616
questions:
1717
- question: |
18-
Can I enable on a subset of machines in a subscription?
18+
Can I enable Defender for Servers on a subset of machines in a subscription?
1919
answer: |
20-
No. When you enable Microsoft Defender for Servers on an Azure subscription or a connected AWS account/GCP project, all of the connected machines are protected by Defender for Servers. This includes servers that don't have the Log Analytics/Azure Monitor agent installed.
20+
No. When you enable Microsoft Defender for Servers on an Azure subscription or on a connected AWS account or GCP project, all connected machines are protected by Defender for Servers. This includes servers that don't have the Log Analytics agent or Azure Monitor agent installed.
2121
2222
- question: |
23-
Can I get a discount if I already have Microsoft Defender for Endpoint license?
23+
Can I get a discount if I already have a Microsoft Defender for Endpoint license?
2424
answer: |
25-
If you already have a license for Microsoft Defender for Endpoint for Servers, you won't have to pay for that part of your Microsoft Defender for Servers Plan 2 license.
25+
If you already have a license for Microsoft Defender for Endpoint for Servers, you don't pay for that part of your Microsoft Defender for Servers Plan 2 license.
2626
27-
To request your discount, contact Defender for Cloud's support team via the portal.
27+
To request your discount, contact the Defender for Cloud support team through the Azure portal.
2828
29-
- You'll need to provide the relevant workspace ID, region, and number of Defender for Endpoint for servers licenses applied for machines in the given workspace.
30-
- The discount will be effective starting from the approval date, and won't take place retroactively.
29+
- Provide the relevant workspace ID, region, and number of Defender for Endpoint for Servers licenses that are applied to machines in the workspace.
30+
- The discount is effective starting on the approval date. The discount isn't retroactive.
3131
3232
- question: |
3333
What servers do I pay for in a subscription?
3434
answer: |
35-
When you enable Defender for Servers on a subscription, you're charged for all machines, in accordance with their power state.
35+
When you enable Defender for Servers on a subscription, you're charged for all machines based on their power states.
3636
3737
**Azure VMs:**
3838
3939
State | Details | Billing
4040
--- | --- | ---
41-
Starting | VM starting up | Not billed
42-
Running | Normal working state | Billed
43-
Stopping | Transitional, will move to Stopped state when complete. | Billed
44-
Stopped | VM shut down from within guest OS or using PowerOff APIs. Hardware is still allocated and the machine remains on the host. | Billed
45-
Deallocating | Transitional, will move to Deallocated state when complete. | Not billed
41+
Starting | VM starting up. | Not billed
42+
Running | Normal working state. | Billed
43+
Stopping | Transitional. Moves to Stopped state when finished. | Billed
44+
Stopped | VM shut down from within guest OS or by using PowerOff APIs. Hardware is still allocated, and the machine remains on the host. | Billed
45+
Deallocating | Transitional. Moves to Deallocated state when finished. | Not billed
4646
Deallocated | VM stopped and removed from the host. | Not billed
4747
4848
**Azure Arc machines:**
4949
50-
**State** | **Details* | **Billing**
50+
**State** | **Details** | **Billing**
5151
--- | --- | ---
52-
Connecting | Servers connected but heartbeat not yet received | Not billed
53-
Connected | Receiving regular heartbeat from Connected Machine agent | Billed
54-
Offline/Disconnected | No heartbeat received with 15-30 minutes | Not billed
55-
Expired | If disconnected for 45 days status can change to Expired. | Not billed
52+
Connecting | Servers connected, but heartbeat not yet received. | Not billed
53+
Connected | Receiving regular heartbeat from Connected Machine agent. | Billed
54+
Offline/Disconnected | No heartbeat received in 15-30 minutes. | Not billed
55+
Expired | If disconnected for 45 days, status might change to Expired. | Not billed
5656
5757
5858
- question: |
59-
Do I need to enable on the subscription and workspace?
59+
Do I need to enable Defender for Servers on the subscription and on the workspace?
6060
answer: |
61-
When you enable the Servers plan on the subscription level, Defender for Cloud automatically enables the plan on your default workspaces automatically. If you're using a custom workspace, you need to select it to enable the plan. Note that:
61+
When you enable a Defender for Servers plan at the subscription level, Defender for Cloud automatically enables the plan on your default workspaces. If you use a custom workspace, select the workspace to enable the plan. Here's more information:
6262
6363
- If you turn on Defender for Servers for a subscription and for a connected custom workspace, you aren't charged for both. The system identifies unique VMs.
6464
- If you enable Defender for Servers on cross-subscription workspaces:
65-
- For the Log Analytics agent, connected machines from all subscriptions are billed, including subscriptions that don't have the servers plan enabled.
65+
- For the Log Analytics agent, connected machines from all subscriptions are billed, including subscriptions that don't have the Defender for Servers plan enabled.
6666
- For the Azure Monitor agent, billing and feature coverage for Defender for Servers depends only on the plan being enabled in the subscription.
6767
6868
6969
- question: |
70-
Is the free allowance per workspace or per machine?
70+
Is the free allowance applied per workspace or per machine?
7171
answer: |
72-
You get 500-MB free data ingestion per day, for every VM connected to the workspace. This is specifically for the security data types that are directly collected by Defender for Cloud.
72+
For every VM that's connected to the workspace, you get 500 MB of free data ingestion per day. The allowance is specifically for the security data types that are directly collected by Defender for Cloud.
7373
74-
This data is a daily rate averaged across all nodes. Your total daily free limit is equal to [number of machines] x 500 MB. So even if some machines send 100 MB and others send 800 MB, if the total doesn't exceed your total daily free limit, you won't be charged extra.
74+
This allowance is a daily rate that's averaged across all nodes. Your total daily free limit is equal to \[number of machines\] × 500 MB. Even if some machines send 100 MB and others send 800 MB, if the total doesn't exceed your total daily free limit, you aren't charged extra.
7575
7676
- question: |
7777
What data types are included in the daily allowance?
7878
answer: |
79-
Defender for Cloud's billing is closely tied to the billing for Log Analytics. [Microsoft Defender for Servers](defender-for-servers-introduction.md) provides a 500 MB/node/day allocation for machines against the following subset of [security data types](/azure/azure-monitor/reference/tables/tables-category#security):
79+
Defender for Cloud billing is closely tied to the billing for Log Analytics. [Microsoft Defender for Servers](defender-for-servers-introduction.md) provides an allocation of 500 MB per node per day for machines against the following subset of [security data types](/azure/azure-monitor/reference/tables/tables-category#security):
8080
8181
- [SecurityAlert](/azure/azure-monitor/reference/tables/securityalert)
8282
- [SecurityBaseline](/azure/azure-monitor/reference/tables/securitybaseline)
@@ -88,17 +88,17 @@ sections:
8888
- [ProtectionStatus](/azure/azure-monitor/reference/tables/protectionstatus)
8989
- [Update](/azure/azure-monitor/reference/tables/update) and [UpdateSummary](/azure/azure-monitor/reference/tables/updatesummary) when the Update Management solution isn't running in the workspace or solution targeting is enabled.
9090
91-
If the workspace is in the legacy Per Node pricing tier, the Defender for Cloud and Log Analytics allocations are combined and applied jointly to all billable ingested data.
91+
If the workspace is in the legacy per-node pricing tier, the Defender for Cloud and Log Analytics allocations are combined and applied jointly to all billable ingested data.
9292
9393
- question: |
94-
Am I charged for machines without Log Analytics installed?
94+
Am I charged for machines that don't have Log Analytics installed?
9595
answer: |
96-
Yes. When you enable Microsoft Defender for Servers on an Azure subscription or a connected AWS/GCP account/project, you'll be charged for all machines that are connected to your Azure subscription or AWS account. The term machines include Azure virtual machines, Azure Virtual Machine Scale Sets instances, and Azure Arc-enabled servers. Machines that don't have Log Analytics installed are covered by protections that don't depend on the Log Analytics agent.
96+
Yes. When you enable Defender for Servers on an Azure subscription, connected AWS account, or connected GCP project, you're charged for all machines that are connected to your Azure subscription or your AWS account. The term *machines* includes Azure virtual machines, instances of Azure Virtual Machine Scale Sets, and Azure Arc-enabled servers. Machines that don't have Log Analytics installed are covered by protections that don't depend on the Log Analytics agent.
9797
9898
- question: |
9999
If an agent reports to multiple workspaces, am I charged twice?
100100
answer: |
101-
If a machine, reports to multiple workspaces, and all of them have Defender for Servers enabled, the machines will be billed for each attached workspace.
101+
If a machine reports to multiple workspaces and all of them have Defender for Servers enabled, the machines are billed for each attached workspace.
102102
103103
104104
175 KB
Loading

0 commit comments

Comments
 (0)