MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.23k stars 21.4k forks source link

Its not clear, how exactly Defender Plan 2 is deployed #118898

Open abe-cyb87 opened 8 months ago

abe-cyb87 commented 8 months ago

Hi, based on this learn article, its not clear, how Defender for Endpoint Plan 2 Agent is deployed in a Subscription.

According to the learn article, the Agent is deployed automatically, if defender plan 1 is selected, and the toggle switch in the environmemt settings is turned to "on".

What are the requirements, to deploy Defender Plan 2 Agents to all VMs in a Subscription? Is the Defender Plan 2 Agent deployed automatically to all VMs, in the same manner as the defender plan 1 agent (see above)? Do we still need a Azure Policy? Or is a Azure Policy created automatically? (maybe hidden?)

Is it needed to connect all VMs with a Log analytics workspace through the new Azure Monitor Agent (AMA) ?

The Part "Enable the plan at resource level" (https://learn.microsoft.com/en-us/azure/defender-for-cloud/tutorial-enable-servers-plan#enable-the-plan-at-the-resource-level) is also not clear. How exactly can one exclude a VM from the defender deployment?

Regards


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

SaibabaBalapur-MSFT commented 8 months ago

@abe-cyb87 Thanks for your feedback! We will investigate and update as appropriate.

ElazarK commented 8 months ago

reassign:AlizaBernstein

AlizaBernstein commented 8 months ago

Work item created https://dev.azure.com/msft-skilling/Content/_workitems/edit/200670/

label:"backlog-item-created"

TPavanBalaji commented 6 months ago

@dcurwin Could you please review it.