Azure defender for subset of services/resources

%3CLINGO-SUB%20id%3D%22lingo-sub-2073646%22%20slang%3D%22en-US%22%3EAzure%20defender%20for%20subset%20of%20services%2Fresources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2073646%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20There%2C%3C%2FP%3E%3CP%3EI%20am%20new%20to%20ASC.%20I%20enabled%20azure%20defender%20(trial)%20for%20my%20subscription%20and%20now%20want%20to%20only%20enable%20azure%20defender%20for%20my%20production%20workloads%20not%20the%20dev%2Ftest.%20We%20have%20all%20the%20workloads%20under%20same%20subscription.%20Is%20it%20possible%20to%20do%20that%20%3F%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3EMuhammad%20Hamza%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2073816%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20defender%20for%20subset%20of%20services%2Fresources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2073816%22%20slang%3D%22en-US%22%3EHello%20Muhammad%2C%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20one%20is%20answered%20very%20quickly%20%3B)%3C%2Fimg%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fnl-nl%2Fazure%2Fsecurity-center%2Fsecurity-center-pricing%23can-i-enable-azure-defender-for-servers-on-a-subset-of-servers-in-my-subscription%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fnl-nl%2Fazure%2Fsecurity-center%2Fsecurity-center-pricing%23can-i-enable-azure-defender-for-servers-on-a-subset-of-servers-in-my-subscription%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20this%20answers%20your%20question.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2073834%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20defender%20for%20subset%20of%20services%2Fresources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2073834%22%20slang%3D%22en-US%22%3EHi%20There%2C%3CBR%20%2F%3EI%20already%20read%20this%20article%2C%20it%20only%20tells%20about%20VM%2C%20Our%20workload%20have%20lots%20of%20app%20service%20plans%2C%20storage%20accounts%2C%20SQL%20servers%2C%20key%20vaults%20and%20many%20other%20resources.%20we%20have%20all%20of%20these%20resources%20for%20dev%20and%20prod%20under%20a%20single%20subscription.%20Can%20we%20somehow%20enable%20azure%20defender%20for%20a%20subset%20of%20these%20resources%20like%20on%20RG%20level%20or%20anything%20like%20that%20or%20even%20at%20resource%20level%20%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2075802%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20defender%20for%20subset%20of%20services%2Fresources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2075802%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Muhammad%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20is%20no%20binary%20answer%20to%20your%20question.%20For%20certain%20resources%20(SQL%2C%20Storage%20accounts)%20Azure%20Defender%20currently%20can%20be%20(if%20you%20need%20granularity%2C%20assuming%20it%20is%20not%20enabled%20on%20the%20subscription)%20enabled%20at%20the%20resource%20level.%20For%20all%20other%20supported%20resource%20types%20you%20need%20to%20enable%20Defender%20at%20the%20subscription%20level%20to%20get%20full%20benefit%20of%20it.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlso%2C%20it's%20probably%20not%20ideal%20to%20have%20both%20production%20and%20non-production%20resources%20in%20the%20same%20subscription%20from%20manageability%20and%20security%20perspective.%20Please%20review%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-adoption-framework%2Fdecision-guides%2Fsubscriptions%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ESubscription%20decision%20guide%20-%20Cloud%20Adoption%20Framework%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20are%20considering%20implementing%20more%20flexibility%2Foptions%20to%20include%2Fexclude%20resources%20from%20the%20defender%20coverage%20but%20don't%20have%20any%20ETA%20to%20share%20at%20the%20moment.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi There,

I am new to ASC. I enabled azure defender (trial) for my subscription and now want to only enable azure defender for my production workloads not the dev/test. We have all the workloads under same subscription. Is it possible to do that ? 

Thanks

Muhammad Hamza

4 Replies

Hello Muhammad,

If you only mean VM's by "workload" then this one is answered very quickly ;)

https://docs.microsoft.com/nl-nl/azure/security-center/security-center-pricing#can-i-enable-azure-de...

Hope this answers your question.

Hi There,
I already read this article, it only tells about VM, Our workload have lots of app service plans, storage accounts, SQL servers, key vaults and many other resources. we have all of these resources for dev and prod under a single subscription. Can we somehow enable azure defender for a subset of these resources like on RG level or anything like that or even at resource level ?

Hi Muhammad,

 

There is no binary answer to your question. For certain resources (SQL, Storage accounts) Azure Defender currently can be (if you need granularity, assuming it is not enabled on the subscription) enabled at the resource level. For all other supported resource types you need to enable Defender at the subscription level to get full benefit of it.

 

Also, it's probably not ideal to have both production and non-production resources in the same subscription from manageability and security perspective. Please review: Subscription decision guide - Cloud Adoption Framework | Microsoft Docs

 

We are considering implementing more flexibility/options to include/exclude resources from the defender coverage but don't have any ETA to share at the moment.

@Stanislav Belov 

 

Thank you . Even we are looking for exceptions and its good to know that there is a plan to have this features to be incorporated .