You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/faq-defender-for-servers.yml
+33-33Lines changed: 33 additions & 33 deletions
Original file line number
Diff line number
Diff line change
@@ -1,82 +1,82 @@
1
1
### YamlMime:FAQ
2
2
metadata:
3
-
title: FAQ — Microsoft Defender for Servers
4
-
description: This article provides answers to common questions about Microsoft Defender for Servers.
3
+
title: FAQ for Microsoft Defender for Servers
4
+
description: Get answers to common questions about Microsoft Defender for Servers.
5
5
ms.topic: faq
6
6
ms.service: defender-for-cloud
7
7
author: bmansheim
8
8
ms.author: benmansheim
9
9
ms.date: 11/29/2022
10
-
title: Frequently asked questions – Defender for Servers
11
-
summary: This article answers common questions about Microsoft Defender for Servers.
10
+
title: Frequently asked questions for Defender for Servers
11
+
summary: Get answers to common questions about Microsoft Defender for Servers.
12
12
13
13
14
14
sections:
15
15
- name: Ignored
16
16
questions:
17
17
- question: |
18
-
Can I enable on a subset of machines in a subscription?
18
+
Can I enable Defender for Servers on a subset of machines in a subscription?
19
19
answer: |
20
-
No. When you enable Microsoft Defender for Servers on an Azure subscription or a connected AWS account/GCP project, all of the connected machines are protected by Defender for Servers. This includes servers that don't have the Log Analytics/Azure Monitor agent installed.
20
+
No. When you enable Microsoft Defender for Servers on an Azure subscription or on a connected AWS account or GCP project, all connected machines are protected by Defender for Servers. This includes servers that don't have the Log Analytics agent or Azure Monitor agent installed.
21
21
22
22
- question: |
23
-
Can I get a discount if I already have Microsoft Defender for Endpoint license?
23
+
Can I get a discount if I already have a Microsoft Defender for Endpoint license?
24
24
answer: |
25
-
If you already have a license for Microsoft Defender for Endpoint for Servers, you won't have to pay for that part of your Microsoft Defender for Servers Plan 2 license.
25
+
If you already have a license for Microsoft Defender for Endpoint for Servers, you don't pay for that part of your Microsoft Defender for Servers Plan 2 license.
26
26
27
-
To request your discount, contact Defender for Cloud's support team via the portal.
27
+
To request your discount, contact the Defender for Cloud support team through the Azure portal.
28
28
29
-
- You'll need to provide the relevant workspace ID, region, and number of Defender for Endpoint for servers licenses applied for machines in the given workspace.
30
-
- The discount will be effective starting from the approval date, and won't take place retroactively.
29
+
- Provide the relevant workspace ID, region, and number of Defender for Endpoint for Servers licenses that are applied to machines in the workspace.
30
+
- The discount is effective starting on the approval date. The discount isn't retroactive.
31
31
32
32
- question: |
33
33
What servers do I pay for in a subscription?
34
34
answer: |
35
-
When you enable Defender for Servers on a subscription, you're charged for all machines, in accordance with their power state.
35
+
When you enable Defender for Servers on a subscription, you're charged for all machines based on their power states.
36
36
37
37
**Azure VMs:**
38
38
39
39
State | Details | Billing
40
40
--- | --- | ---
41
-
Starting | VM starting up | Not billed
42
-
Running | Normal working state | Billed
43
-
Stopping | Transitional, will move to Stopped state when complete. | Billed
44
-
Stopped | VM shut down from within guest OS or using PowerOff APIs. Hardware is still allocated and the machine remains on the host. | Billed
45
-
Deallocating | Transitional, will move to Deallocated state when complete. | Not billed
41
+
Starting | VM starting up. | Not billed
42
+
Running | Normal working state. | Billed
43
+
Stopping | Transitional. Moves to Stopped state when finished. | Billed
44
+
Stopped | VM shut down from within guest OS or by using PowerOff APIs. Hardware is still allocated, and the machine remains on the host. | Billed
45
+
Deallocating | Transitional. Moves to Deallocated state when finished. | Not billed
46
46
Deallocated | VM stopped and removed from the host. | Not billed
47
47
48
48
**Azure Arc machines:**
49
49
50
-
**State** | **Details* | **Billing**
50
+
**State** | **Details** | **Billing**
51
51
--- | --- | ---
52
-
Connecting | Servers connected but heartbeat not yet received | Not billed
Offline/Disconnected | No heartbeat received in 15-30 minutes. | Not billed
55
+
Expired | If disconnected for 45 days, status might change to Expired. | Not billed
56
56
57
57
58
58
- question: |
59
-
Do I need to enable on the subscription and workspace?
59
+
Do I need to enable Defender for Servers on the subscription and on the workspace?
60
60
answer: |
61
-
When you enable the Servers plan on the subscription level, Defender for Cloud automatically enables the plan on your default workspaces automatically. If you're using a custom workspace, you need to select it to enable the plan. Note that:
61
+
When you enable a Defender for Servers plan at the subscription level, Defender for Cloud automatically enables the plan on your default workspaces. If you use a custom workspace, select the workspace to enable the plan. Here's more information:
62
62
63
63
- If you turn on Defender for Servers for a subscription and for a connected custom workspace, you aren't charged for both. The system identifies unique VMs.
64
64
- If you enable Defender for Servers on cross-subscription workspaces:
65
-
- For the Log Analytics agent, connected machines from all subscriptions are billed, including subscriptions that don't have the servers plan enabled.
65
+
- For the Log Analytics agent, connected machines from all subscriptions are billed, including subscriptions that don't have the Defender for Servers plan enabled.
66
66
- For the Azure Monitor agent, billing and feature coverage for Defender for Servers depends only on the plan being enabled in the subscription.
67
67
68
68
69
69
- question: |
70
-
Is the free allowance per workspace or per machine?
70
+
Is the free allowance applied per workspace or per machine?
71
71
answer: |
72
-
You get 500-MB free data ingestion per day, for every VM connected to the workspace. This is specifically for the security data types that are directly collected by Defender for Cloud.
72
+
For every VM that's connected to the workspace, you get 500 MB of free data ingestion per day. The allowance is specifically for the security data types that are directly collected by Defender for Cloud.
73
73
74
-
This data is a daily rate averaged across all nodes. Your total daily free limit is equal to [number of machines] x 500 MB. So even if some machines send 100 MB and others send 800 MB, if the total doesn't exceed your total daily free limit, you won't be charged extra.
74
+
This allowance is a daily rate that's averaged across all nodes. Your total daily free limit is equal to \[number of machines\] × 500 MB. Even if some machines send 100 MB and others send 800 MB, if the total doesn't exceed your total daily free limit, you aren't charged extra.
75
75
76
76
- question: |
77
77
What data types are included in the daily allowance?
78
78
answer: |
79
-
Defender for Cloud's billing is closely tied to the billing for Log Analytics. [Microsoft Defender for Servers](defender-for-servers-introduction.md) provides a 500 MB/node/day allocation for machines against the following subset of [security data types](/azure/azure-monitor/reference/tables/tables-category#security):
79
+
Defender for Cloud billing is closely tied to the billing for Log Analytics. [Microsoft Defender for Servers](defender-for-servers-introduction.md) provides an allocation of 500 MB per node per day for machines against the following subset of [security data types](/azure/azure-monitor/reference/tables/tables-category#security):
- [Update](/azure/azure-monitor/reference/tables/update) and [UpdateSummary](/azure/azure-monitor/reference/tables/updatesummary) when the Update Management solution isn't running in the workspace or solution targeting is enabled.
90
90
91
-
If the workspace is in the legacy Per Node pricing tier, the Defender for Cloud and Log Analytics allocations are combined and applied jointly to all billable ingested data.
91
+
If the workspace is in the legacy per-node pricing tier, the Defender for Cloud and Log Analytics allocations are combined and applied jointly to all billable ingested data.
92
92
93
93
- question: |
94
-
Am I charged for machines without Log Analytics installed?
94
+
Am I charged for machines that don't have Log Analytics installed?
95
95
answer: |
96
-
Yes. When you enable Microsoft Defender for Servers on an Azure subscription or a connected AWS/GCP account/project, you'll be charged for all machines that are connected to your Azure subscription or AWS account. The term machines include Azure virtual machines, Azure Virtual Machine Scale Sets instances, and Azure Arc-enabled servers. Machines that don't have Log Analytics installed are covered by protections that don't depend on the Log Analytics agent.
96
+
Yes. When you enable Defender for Servers on an Azure subscription, connected AWS account, or connected GCP project, you're charged for all machines that are connected to your Azure subscription or your AWS account. The term *machines* includes Azure virtual machines, instances of Azure Virtual Machine Scale Sets, and Azure Arc-enabled servers. Machines that don't have Log Analytics installed are covered by protections that don't depend on the Log Analytics agent.
97
97
98
98
- question: |
99
99
If an agent reports to multiple workspaces, am I charged twice?
100
100
answer: |
101
-
If a machine, reports to multiple workspaces, and all of them have Defender for Servers enabled, the machines will be billed for each attached workspace.
101
+
If a machine reports to multiple workspaces and all of them have Defender for Servers enabled, the machines are billed for each attached workspace.
0 commit comments