Forum Discussion
CSP_MO
Sep 09, 2021Copper Contributor
Possible to Disable Defender on individual Storage Accounts?
Hi folks, The gist is that we have Azure Defender enabled at a Subscription level. With that comes Advanced Threat Protection for Storage Accounts which is charged per transaction within those S...
- Oct 12, 2021
We do not recommend excluding storage accounts from the Azure Defender, but If you want to perform cost optimization and you are considering the exclusion of specific storage accounts that are characterized with high traffic from the Azure Defender threat protection (e.g. storage accounts that are not open to the internet and do not contain sensitive data), it is possible to estimate the Defender for Storage costs first by following the blog post here.
To exclude specific storage accounts from Azure Defender, follow the following steps:
Step 1:
Enter the Tags section from the storage account(s) menu, and assign the following tag for the desired account(s) you would like to exclude:
Name
AzDefenderPlanAutoEnable
Value
off
After assigning the Tag name and value, click Apply.
It should look like the screenshot below after applying:
The tag excludes the account from getting updates from the subscription level enablement policy, these updates that occurs daily (If required, you can find here more information on assigning tags)
Step 2:
Disable "Azure Defender" on the desired accounts(s) by performing one of the following actions:
Option A (PowerShell command):
Run the following command in PowerShell on the relevant resource(s):
Disable-AzSecurityAdvancedThreatProtection -ResourceId <resourceId>(the cmdlet is documented here)
Option B - Enable/Disable on the account level (from the Azure Security Center portal):
Security Center ➡ Pricing & settings ➡ Select the desired subscription ➡ Toggle Storage off/on (and click Save)
StanislavBelov
Microsoft
Sep 15, 2021This option to selectively disable Defender for certain storage accounts is currently being tested (closed private preview) and will likely be released later this year. No solid ETA though.
- lctimcolesOct 01, 2021Copper ContributorHi there, we'd also be interested in testing this feature. We are currently using SAs for FSLogix which are generating significant Defender costs.
- CSP_MOSep 15, 2021Copper ContributorThank you Stanislav,
Is there a way to petition to join the beta?
Failing that, is it understood that the Disable-AzSecurityAdvancedThreatProtection cmdlet is not expected to disable billing for the ATP feature?- StanislavBelovSep 16, 2021
Microsoft
There is something else you need to do before running that cmdlet. Can't disclose all details publicly yet. Let me double check if this preview is still open for new participants.- Brendon LoboSep 22, 2021Copper Contributori am interested too for my customers.