Hello,
It is not 100% clear to me whether or not I need Microsoft Defender for Cloud for servers for the servers in the VMSS Scaleset.
Looking at your article and given the fact that it is vCore based it almost looks like it replaces it.
However, technically it would be possible to install other systems and services and Qualys vulnerability scan only comes with Defender for Servers.
So in a practical example.
I am looking at
- Microsoft Defender for Servers Plan 2
- Microsoft Defender for Containers
Let's say I have 8 user node servers with 4vCores each and 2 system node servers, i.e. 2 VMSS Scalesets.
So what is my Defender for Cloud licensing?
40 vCore for Containers?
Do I also need to accomodate server plans? Or is this superfluous as the container protection is adequate for server in Scalesets created through AKS provisioning?
If I had manually created the servers I would think I need 10 server plans? But then also since we only have 2 VMSS Scalesets this seems wrong as technically we only have 2 images to scan.
Can you give any clear example on how Microsoft envisions Microsoft Defender for Cloud to be configured for servers in the VMSS Scalesets of the AKS clusters?
Many thanks for your kind help.
Dietmar