Microsoft Defender for Cloud
Cloud and workloads

Prepare for retirement of the Log Analytics agent

In brief

The documentation now describes the Log Analytics (MMA) agent as retired in November 2024, updates affected Defender for Servers features, and clarifies replacement recommendations and onboarding guidance.

What Defender admins need to know

Administrators using legacy MMA onboarding should connect non-Azure servers through Azure Arc and review the required actions for affected Defender for Servers deployments. MMA auto-provisioning can no longer be enabled on existing subscriptions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prepare for retirement of the Log Analytics agent

The Log Analytics agent, also known as the Microsoft Monitoring Agent (MMA), retired in November 2024 as described in the Defender for Cloud Log Analytics agent retirement plan. As a result,Because of this retirement, the Defender for Servers and Defender for SQL on machines plans in Microsoft Defender for Cloud will be updated, and features that rely on the Log Analytics agent will be redesigned.

This article summarizes plans for the Log Analytics agent (MMA) retirement.

Prepare Defender for Servers

The Defender for Servers plan uses the Log Analytics agent in general availability (GA) and in AMA for Defender for Servers agent and feature support (in preview). Here's what's happening with these features going forward:

To simplify onboarding, all Defender for Servers security features and capabilities will be provided with a single agent (Microsoft Defender for Endpoint), complemented by agentless machine scanning, without any dependency on Log Analytics agent or AMA.

Feature functionality

The following table summarizes how Defender for Servers features will be provided. Most features are already generally available using Defender for Endpoint integration or agentless machine scanning. The rest ofremaining Defender for Servers features listed in the featuresfollowing table will either be available in GA by the time the MMA is retired, or will be deprecated.

| Feature | Current support | New support | New experience status | |----|----|----|----|--- | OS-level threat detection | Log Analytics agent | Defender for Endpoint agent integration | Functionality with the Defender for Endpoint agent is GA. | | Adaptive application controls | Log Analytics agent (GA), AMA (Preview) | --- | The adaptive application control feature is set to be deprecated in August 2024. | | Endpoint protection discovery recommendations | Recommendations that are available through the Foundational Cloud Security Posture Management (CSPM) plan and Defender for Servers, using the Log Analytics agent (GA), AMA (Preview) | Agentless machine scanning | - Functionality with agentless machine scanning has been released to preview in early 2024 as part of Defender for Servers Plan 2 and the Defender CSPM plan.
- Azure VMs, Google Cloud Platform (GCP) instances, and Amazon Web Services (AWS) instances are supported. On-premises machines are not supported.| | Missing OS update recommendation | Recommendations available in the Foundational CSPM and Defender for Servers plans using the Log Analytics agent. | Integration with Update Manager, Microsoft | New recommendations based on Azure Update Manager integration reached general availability (see OS update recommendations release notes), with no agent dependencies. | | OS misconfigurations (Microsoft Cloud Security Benchmark) | Recommendations that are available through the Foundational CSPM and Defender for Servers plans using the Log Analytics agent, Guest Configuration extension (Preview). | Guest Configuration extension, as part of Defender for Servers Plan 2.| - Functionality based on Guest Configuration extension will be released to GA in September 2024
- For Defender for Cloud customers only: functionality with the Log Analytics agent will be deprecated in November 2024.
- Support of this feature for Docker-hub and Azure Virtual Machine Scale Sets will be deprecated in Aug 2024.| | File integrity monitoring | Log Analytics agent, AMA (Preview) | Defender for Endpoint agent integration | Functionality with the Defender for Endpoint agent will be available in August 2024.
- For Defender for Cloud customers only: functionality with the Log Analytics agent will be deprecated in November 2024.
- Functionality with AMA will deprecate when the Defender for Endpoint integration is released.|

 - On **newly created subscriptions**, auto provisioning can no longer be enabled and is automatically turned off.
  1. End of November 2024 - the capabilityMMA auto provisioning will be disabled on subscriptions that have not yet switched it off. From that point forward, it is no longer possible to enable the capabilityMMA auto provisioning on existing subscriptions.

The 500-MB benefit for data ingestion

  • The onboarding experience for onboarding new non-Azure machines to Defender for Servers using Log Analytics agents and workspaces is removed from the Inventory and Getting started blades in the Defender for Cloud portal.

  • To avoid losing security coverage on the affected machines connected to a Log Analytics Workspace, with the Agent retirement:

  • If you onboarded non-Azure servers (both on-premises and multicloud) using the legacy Log Analytics agent onboarding for non-Azure machines, you should now connect these machines via Azure Arc-enabled servers to Defender for Servers Plan 2 Azure subscriptions and connectors. For more information, see Azure Arc server deployment options aboutfor deploying Arc machines at scale.

    • If you used the legacy approach to enable Defender for Servers Plan 2 on selected Azure VMs, we recommend enabling Defender for Servers Plan 2 on the Azure subscriptions for these machines. You can then exclude individual machines from the Defender for Servers coverage using the Defender for Servers per-resource configuration.

This is a summary ofThe following table summarizes the required action for each of the serversserver onboarded to Defender for Servers Plan 2 through the legacy approach:

Machine type Action required to preserve security coverage

System updates and patches are crucial for keeping the security and health of your machines. Updates often contain security patches for vulnerabilities that, if left unfixed, are exploitable by attackers.

System updates recommendations were previously provided by the Defender for Cloud Foundational CSPM and the Defender for Servers plans using the Log Analytics agent. ThisThe previous Log Analytics agent-based system updates recommendation experience has been replaced by security recommendations that are gathered using Azure Update Manager and constructed out of 2 new recommendations:

  1. Machines should be configured to periodically check for missing system updates
Recommendation Agent Supported resources Deprecation date Replacement recommendation
System updates should be installed on your machines MMA Azure & non-Azure (Windows & Linux) August 2024 System updates should be installed on your machines (powered by Azure Update Manager)
System updates on virtual machine scale sets should be installed MMA Azure Virtual Machine Scale Sets August 2024 No replacement

How do I prepare for the new recommendations?

Endpoint protection recommendations experience - changes and migration guidance

Endpoint discovery and recommendations were previously provided by the Defender for Cloud Foundational CSPM and the Defender for Servers plans using the Log Analytics agent in GA, or in preview via the AMA. TheseThe previous MMA/AMA-based endpoint discovery and recommendation experiences have been replaced by security recommendations that are gathered using agentless machine scanning.

Endpoint protection recommendations are constructed in two stages. The first stage is endpoint detection and response solution discovery of an endpoint detection and response solution.. The second stage is assessment of the solution's configuration. The following tables provide details of the current and new experiences for each stage.

Learn how to manage the new endpoint detection and response recommendations (agentless).

Endpoint detection and response solution - discovery

The following table compares the current and new discovery experiences for endpoint detection and response solutions.

| Area | Current experience (based on AMA/MMA)| New experience (based on agentless machine scanning) | |----|----|----|--- |What's needed to classify a resource as healthy? | An anti-virus is in place. | An endpoint detection and response solution is in place. |

Endpoint detection and response solution - configuration assessment

The following table compares the current and new configuration assessment experiences for endpoint detection and response solutions.

| Area | Current experience (based on AMA/MMA)| New experience (based on agentless machine scanning) | |----|----|----|--- | Resources are classified as unhealthy if one or more of the security checks aren't healthy. | Three security checks:
- Real time protection is off
- Signatures are out of date.
- Both quick scan and full scan aren't run for seven days. | Three security checks:
- Anti-virus is off or partially configured
- Signatures are out of date
- Both quick scan and full scan aren't run for seven days. |

| Recommendation | Agent | Supported resources | Deprecation date | Replacement recommendation | |----|----|----|----|----|--- | Endpoint protection should be installed on your machines (public) | MMA/AMA | Azure & non-Azure (Windows & Linux) | July 2024 | New agentless endpoint protection recommendation | | Endpoint protection health issues should be resolved on your machines (public)| MMA/AMA | Azure (Windows) | July 2024 | New agentless endpoint protection recommendation | | Endpoint protection health failures on virtual machine scale sets should be resolved | MMA | Azure Virtual Machine Scale Sets | August 2024 | No replacement | | Endpoint protection solution should be installed on virtual machine scale sets | MMA | Azure Virtual Machine Scale Sets | August 2024 | No replacement | | Endpoint protection solution should be on machines | MMA | Non-Azure resources (Windows)| August 2024 | No replacement | | Install endpoint protection solution on your machines | MMA | Azure and non-Azure (Windows) | August 2024 | New agentless recommendation | | Endpoint protection health issues on machines should be resolved | MMA | Azure and non-Azure (Windows and Linux) | August 2024 | New agentless recommendation. |

The new agentless endpoint protection recommendations experience based on agentless machine scanning support both Windows and Linux OS across multicloud machines.

How will the replacement work?

What's happening with secure score?

The following points explain how secure score is affected during the transition from MMA-based to agentless endpoint protection recommendations.

  • Recommendations that are currently in GA will continue to affect secure score.
  • Current and upcoming new recommendations are located under the same Microsoft Cloud Security Benchmark control, ensuring that there's no duplicate impact on secure score.

How do I prepare for the new recommendations?

To prepare for the new agentless endpoint protection recommendations, take the following actions:

File Integrity Monitoring experience - changes and migration guidance

Microsoft Defender for Servers Plan 2 now offers a new File Integrity Monitoring (FIM) solution powered by Microsoft Defender for Endpoint (MDE) integration. Once FIM powered by MDE is public,generally available, the FIM powered by AMA experience in the Defender for Cloud portal will be removed. In November, FIM powered by MMA will be deprecated.

Migration from FIM over AMA

  • New events will stop being collected on the selected scope.
  • The historical events that already were collected remain stored in the relevant workspace under the ConfigurationChange table in the Change Tracking section. These events will remain available in the relevant workspace according to the retention period defined in this workspace. For more information, see How retention and archiving work.

Baseline experience changes and migration guidance

The baselines misconfiguration feature on VMs is designed to ensure that your VMs adhere to security best practices and organizational policies. Baselines misconfiguration evaluates the configuration of your VMs against the predefined security baselines, and identifies any deviations, or misconfigurations that could pose a risk to your environment.

Install Azure Policy guest configuration

In order to continue receiving the baseline experience, you need to enable the Defender for Servers Plan 2 and install the Azure Policy guest configuration. This will ensureEnabling Defender for Servers Plan 2 and installing Azure Policy guest configuration ensures that you continue to receive the same recommendations and hardening guidance that you have been receiving through the baseline experience.

Depending on your environment, you may need to take the following steps:

- **On-premises machines**: The Azure Policy guest configuration is enabled by default when you [onboard on-premises machines as Azure Arc enabled machine or VMs](/azure/azure-arc/servers/learn/quick-enable-hybrid-vm?branch=main).

Once you have completed the necessary steps to install the Azure Policy guest configuration, you will automatically gain access to the baseline features based on the Azure Policy guest configuration. This will ensureInstalling the Azure Policy guest configuration ensures that you continue to receive the same recommendations and hardening guidance that you have been receiving through the baseline experience.

Changes to recommendations

If a machine is running both the MMA and the Azure Policy guest configuration, you will see duplicate recommendations. The duplication of recommendations occurs because both methods are running at the same time and producing the same recommendations. These duplicates will affect your Compliance and Secure Score.

As a work-around,To avoid duplicate recommendations while both the MMA and Azure Policy guest configuration are running, you can disable the MMA recommendations, "Machines should be configured securely", and "Auto provisioning of the Log Analytics agent should be enabled on subscriptions", by navigating to the Regulatory compliance page in Defender for Cloud.

:::image type="content" source="media/prepare-deprecation-log-analytics-mma-agent/exempt-recommendation.png" alt-text="Screenshot of the regulatory compliance dashboard that shows where one of the MMA recommendations exist." lightbox="media/prepare-deprecation-log-analytics-mma-agent/exempt-recommendation.png":::

```

Plan your Log Analytics agent migration

Migration planning

matrix

We recommend you plan agent migration in accordance with your business requirements. The following migration-planning table summarizes our guidance.

| Are you using Defender for Servers? | Are these Defender for Servers features required in GA: file integrity monitoring, endpoint protection recommendations, security baseline recommendations? | Are you using Defender for SQL servers on machines or AMA log collection? | Migration plan | |----|----|----|----|--- | Yes | Yes | No | 1. Enable Defender for Endpoint integration and agentless machine scanning.
2. Wait for GA of all features with the alternative's platform (you can use preview version earlier).
3. Once features are GA, disable the Log Analytics agent.| | No | --- | No | You can remove the Log Analytics agent now. | | No | --- | Yes | 1. You can migrate to SQL autoprovisioning for AMA now.
2. Disable Log Analytics/Azure Monitor Agent. | | Yes | Yes | Yes | 1. Enable Defender for Endpoint integration and agentless machine scanning.
2. You can use the Log Analytics agent and AMA side-by-side to get all features in GA. See auto-deploy the Azure Monitor Agent for details about running agents side-by-side.
3. Migrate to SQL autoprovisioning for AMA in Defender for SQL on machines. Alternatively, start the migration from Log Analytics agent to AMA in April 2024.
4. Once the migration is finished, disable the Log Analytics agent. | | Yes | No | Yes | 1. Enable Defender for Endpoint integration and agentless machine scanning.
2. You can migrate to SQL autoprovisioning for AMA in Defender for SQL on machines now.
3. Disable the Log Analytics agent. |

Use the MMA migration experience

The MMA migration experience is a tool that helps you migrate from the MMA to the AMA. The experience provides a step-by-step guide to help you migrate your machines from the MMA to the AMA.

With this tool,the MMA migration experience, you can:

  • Migrate servers from the legacy onboarding through the Log analytic workspace.
  • Ensure subscriptions meet all of the prerequisites to receive all of Defender for Servers Plan 2's benefits.

Allow the experience to load and follow the steps to complete the migration.

Next stepsteps

[!div class="nextstepaction"] Upcoming changes to the Defender for Cloud plan and strategy for the Log Analytics agent deprecation