Microsoft Defender for Cloud
Cloud and workloads

Determine data residency requirements and agent considerations for multicloud security

In brief

The article was retitled and restructured with an overview, planning goals, clearer plan-specific data residency sections, and navigation anchors. Wording was also clarified around agents, extensions, SQL discovery, and AWS/GCP resource locations.

What Defender admins need to know

Administrators can use the revised structure to find multicloud data residency and agent considerations more easily; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Determine data residency requirements

Overview

This article is one ofguide helps you determine data residency requirements for a series providing guidance as you design amulticloud deployment that uses cloud security posture management (CSPM) and cloud workload protection platform (CWPP) solution across multicloud resources withsolutions in Microsoft Defender for Cloud.

GoalData residency planning goals

Identify data residency requirements for your multicloud deployment and understand how Defender for Cloud plans and agents affect where data is processed and stored.

Get started with data residency planning

When you protect assets across clouds, identify which plans to enable for your required protection and whether each plan requires agent components.agents.

As part of this analysis, identify regional and legal requirements for data handling.

Agent considerations for data residency

There areConsider data considerations aroundresidency and data handling implications for the agents and extensions used by Defender for Cloud.

  • CSPM: Cloud security posture management (CSPM) functionality in Defender for Cloud is agentless. No agents are required for CSPM to work.
  • CWPP: Cloud workload protection platform (CWPP) functionality in Defender for Cloud can require agents to collect data.

Data residency considerations for Defender for Servers plan

Agents are used in the Defender for Servers plan as follows:

  • The Azure Connected Machine agent is installed on multicloud machines that onboard as Azure Arc machines. Defender for Cloud should be enabled in the subscription in which the Azure Arc machines are located.
  • Defender for Cloud leverages the Connected Machine agent to install extensions (such as Microsoft Defender for Endpoint) that are needed for Defender for Servers functionality.

Data residency considerations for Defender for Containers plan

Defender for Containers protects your multicloud container deployments running in:

Data residency considerations for Defender for Databases

For the Defender for Databases plan in a multicloud scenario, you use Azure Arc to manage multicloud Structured Query Language (SQL) Server databases. The SQL Server instance is installed on a virtual or physical machine connected to Azure Arc.

  • Automatic SQL server discovery and registration needs to be set to On to allow SQL database discovery on the machines.
  • The Azure Connected Machine agent is installed on machines connected to Azure Arc.
  • The Defender for Databases plan should be enabled in the subscription in which the Azure Arc machines are located.
  • The Log Analytics agent for Microsoft Defender SQL Servers should be provisioned on the Azure Arc machines. It collects security-related configuration settings and event logs from machines.
  • Automatic SQL server discovery and registration needs to be set to On to allow SQL database discovery on the machines.

When it comes to the actualFor AWS and GCP resources that are protected by Defender for Cloud, theirthe resource location is setdetermined directly from theby AWS and GCP clouds.GCP.

Next stepsteps

[!div class="nextstepaction"] Determine compliance requirements