Microsoft Defender for Cloud
Cloud and workloads

Estimate costs with the Microsoft Defender for Cloud cost calculator

In brief

The documentation now recommends adding assets from onboarded Azure environments, using scripts for environments not yet onboarded such as AWS or GCP, and uploading the CSV generated by the script. It also adds guidance for manually adding a custom environment and clarifies the permissions overview.

What Defender admins need to know

Administrators can use the updated instructions to select the appropriate workflow and prepare the required CSV and permissions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Add assets from onboarded environments

  1. In Azure environments, select the onboarded environment that you want to include in the cost calculation.

Add assets with a script

  1. In Environment type, choose Azure, AWS, or GCP, and then copy the script to a new *.ps1 file.

    The script only collects information that the user running it has access to.

  2. Run the script in your PowerShell 7.X environment by using a privileged user account. The script collects information about your billable assets and creates a CSV file. It gathers information in two steps. First, it collects the current number of billable assets that usually stay constant. Second, it collects information about billable assets that can change a lot during the month. For these assets, it checks usage over the last 30 days to evaluate the cost. You can stop the script after the first step, which takes a few seconds. Or you can continue to collect the last 30 days of usage for dynamic assets, which might take longer for large accounts.

  3. Upload the CSV file generated by the script into the wizard where you downloaded the script.

  4. Select Defender for Cloud plans. The calculator estimates costs based on your selection and any existing discounts.

Required permissions for scripts

The following permissions overview describes the permissions required to run the scripts for each cloud provider.

Azure

Assign custom assets

To add a custom environment manually, complete the following steps:

  1. Choose a name for the custom environment.
  2. Specify the plans and the number of billable assets for each plan.
  3. Select Asset types that you want to include in the cost calculation.