Microsoft Defender for Cloud
Architecture and deployment

Plan a Defender for Servers deployment

In brief

The documentation now describes 500 MB of free daily ingestion per node for eligible security data and says Defender for Servers Plan 2 must be enabled on the reporting Log Analytics workspace. Data must use a supported collection method, such as Azure Monitor Agent.

What Defender admins need to know

Enable Defender for Servers Plan 2 on the relevant workspace and verify that data is collected through a supported method to receive the stated benefit.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Plan Defender for Servers deployment

| Connect AWS/GCP machines | To protect AWS and GCP machines with Defender for Servers, connect AWS accounts and GCP projects to Defender for Cloud.

You can enable Defender for Cloud plans, including Defender for Servers, as part of the connection process.

To take full advantage of Defender for Servers features, we recommend onboarding AWS and GCP machines as Azure Arc VMs. Installation of the Azure Arc agent is available as part of the connection process. | AWS and GCP machines are successfully onboarded to Defender for Cloud. | | Connect on-premises machines | To protect on-premises machines, we recommend onboarding on-premises machines as Azure Arc VMs.

You can directly onboard on-premises machines to Defender for Cloud. However, with direct onboarding you won't have full access to Defender for Servers Plan 2 features. | On-premises machines are successfully onboarded to Defender for Cloud | | Enable Defender for Servers | Deploy a Defender for Servers plan. | Defender for Cloud starts protecting supported machines within the deployment scope. | | Take advantage of free data ingestion | To take advantage of 500 MB of free daily ingestion per node for specific data types, machines must be running the Azure Monitor Agent (AMA), and be connected to a Log Analytics workspace. Learn more.

The benefit is granted
eligible security data, enable Defender for the supported data typesServers Plan 2 on the Log Analytics workspace to which the machines report. Data must be collected through a supported method, such as Azure Monitor Agent (AMA). Creating a data collection rule alone doesn't enable the benefit. For more information, see Defender for Servers data ingestion benefit. | Free daily ingestion is configured for supported data types. | | Prepare for OS assessment | For Defender for Servers Plan 2 to assess operation system configuration settings against compute security baselines in Microsoft Cloud Security Benchmark, machines must be running the Azure Policy machine configuration extension. Learn more about setting up the extension. | Defender for Servers Plan 2 collects OS configuration information for assessment. | | Set up file integrity monitoring | After enabling Defender for Servers Plan 2, you set up file integrity monitoring after enabling the plan.

You need a Log Analytics workspace for file integrity monitoring. You can use an existing workspace, or create a new workspace when you configure the feature. | Defender for Servers monitors critical file changes. |