Skip to content

Commit f94c16d

Browse files
Merge pull request #251410 from galFenigshtein/docs-editor/upcoming-changes-1694675686
Update upcoming-changes.md
2 parents 1f57282 + ca90c8a commit f94c16d

File tree

1 file changed

+34
-4
lines changed

1 file changed

+34
-4
lines changed

articles/defender-for-cloud/upcoming-changes.md

Lines changed: 34 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -91,16 +91,45 @@ The following table explains how each capability will be provided after the Log
9191

9292
##### Log analytics and Azure Monitoring agents autoprovisioning experience
9393

94-
- The MMA autoprovisioning mechanism and its related policy initiative will remain optional until August 2024.
94+
The current provisioning process that provides the installation and configuration of both agents (MMA/AMA), will be adjusted according to the plan mentioned above: 
9595

96-
- In October 2023, the current shared Log Analytics agent/Azure Monitor agent autoprovisioning mechanism will be updated and applied to the Log Analytics agent only. The Azure Monitor agent related (Public Preview) policy initiatives will be deprecated.
96+
1. MMA auto-provisioning mechanism and its related policy initiative will remain optional and supported until August 2024 through the Defender for Cloud platform.   
97+
1. In October 2023: 
98+
1. The current shared ‘Log Analytics agent’/’Azure Monitor agent’ auto-provisioning mechanism will be updated and applied to ‘Log Analytics agent’ only.  
9799

98-
- The AMA autoprovisioning mechanism will still serve current customers with the Public Preview policy initiative enabled, but they won't be eligible for support. To disable the Azure Monitor agent provisioning, manually remove the policy initiative.
100+
1. **Azure Monitor agent** (AMA) related Public Preview policy initiatives will be deprecated and replaced with the new auto-provisioning process for Azure Monitor agent (AMA), targeting only Azure registered SQL servers (SQL Server on Azure VM/ Arc-enabled SQL Server). 
99101

100-
- If MMA autoprovisioning is enabled and AMA agents are already installed on the machines, MMA won’t be provisioned. However, AMA will remain functional.
102+
1. Current customers with AMA with the Public Preview policy initiative enabled will still be supported but are recommended to migrate to the new policy. 
101103

102104
To ensure the security of your servers and receive all the security updates from Defender for Servers, make sure to have [Defender for Endpoint integration](integration-defender-for-endpoint.md) and [agentless disk scanning](concept-agentless-data-collection.md) enabled on your subscriptions. This will also keep your servers up-to-date with the alternative deliverables.
103105

106+
#### Agents migration planning 
107+
108+
**First, all Defender for Servers customers are advised to enable Defender for Endpoint integration and agentless disk scanning as part of the Defender for Servers offering, at no additional cost.** This will ensure you are automatically covered with the new alternative deliverables, with no additional onboarding required.    
109+
110+
Following that, plan your migration plan according to your organization requirements: 
111+
112+
||Azure Monitor agent (AMA) required (for Defender for SQL or other scenarios)|FIM/EPP discovery/Baselined is required as part of Defender for Server|What should I do|
113+
| -------- | -------- | -------- | -------- |
114+
| |No |Yes |You can remove MMA starting April 2024, using GA version of Defender for Server capabilities according to your needs (preview versions will be available earlier)  |
115+
| |No |No |You can remove MMA starting now |
116+
| |Yes |No |You can start migration from MMA to AMA now |
117+
| |Yes |Yes |You can either start migration from MMA to AMA starting April 2024 or alternatively, you can use both agents side by side starting now. |
118+
119+
**Customers with Log analytics Agent** **(MMA) enabled** 
120+
121+
- If the following features are required in your organization: File Integrity Monitoring (FIM), Endpoint Protection recommendations, OS misconfigurations (security baselines recommendations), you can start retiring from MMA in April 2024 when an alternative will be delivered in GA (preview versions will be available earlier). 
122+
123+
- If the features mentioned above are required in your organization, and Azure Monitor agent (AMA) is required for other services as well, you can start migrating from MMA to AMA in April 2024. Alternatively, use both MMA and AMA to get all GA features, then remove MMA in April 2024. 
124+
125+
- If the features mentioned above are not required, and Azure Monitor agent (AMA) is required for other services, you can start migrating from MMA to AMA now. However, note that the preview Defender for Servers capabilities over AMA will be deprecated in April 2024. 
126+
127+
**Customers with Azure Monitor agent (AMA) enabled** 
128+
129+
No action is required from your end. 
130+
131+
- You’ll receive all Defender for Servers GA capabilities through Agentless and Defender for Endpoint. The following features will be available in GA in April 2024: File Integrity Monitoring (FIM), Endpoint Protection recommendations, OS misconfigurations (security baselines recommendations). The preview Defender for Servers capabilities over AMA will be deprecated in April 2024.
132+
104133
> [!IMPORTANT]
105134
> For more information about how to plan for this change, see [Microsoft Defender for Cloud - strategy and plan towards Log Analytics Agent (MMA) deprecation](https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/microsoft-defender-for-cloud-strategy-and-plan-towards-log/ba-p/3883341).
106135
@@ -265,3 +294,4 @@ Customers will have until September 30, 2023 to resolve this issue. After this d
265294
## Next steps
266295

267296
For all recent changes to Defender for Cloud, see [What's new in Microsoft Defender for Cloud?](release-notes.md).
297+

0 commit comments

Comments
 (0)