Mar 24 2021 04:31 PM
Hi,
somehow I'm not able to figure out how to create a MDE tenant if having only Azure Defender for Servers license which includes the license for MDE for Servers.
When I browse to URL https://securitycenter.windows.com/ I get the "No subscription found" page.
I'm logged in Azure Security Center (https://portal.azure.com/#blade/Microsoft_Azure_Security/SecurityMenuBlade/0) as a user who has Global Administrator role assigned.
What is the correct procedure to provision the MDE tenant in such case?
Kind regards,
Jan
Mar 25 2021 07:14 AM
Hi Jan,
We need to enable MCAS/MDATP integration in Azure Security Center via API.
Please follow the steps in the article: - Settings - Update (Azure Security Center) | Microsoft Docs
Microsoft.Security/settings 2019-01-01 - ARM template reference | Microsoft Docs
May be Azure Security Center community can provide clarity/confirmation.
Thanks,
Balaji R
Mar 25 2021 04:58 PM
@Balaji_R: I'm not sure if this is the same issue that I'm having. In my case I don't even have an active Defender for Endpoint tenant. And cannot simply create one as there are no "user-based" MDE licenses available - this particular Azure tenant is a pure IaaS environment containing just some Windows Server VMs and an active Azure Defender for Servers subscription (which includes a license for MDE for Servers).
Should I request a MDE trial subscription, assign the MDE license to one of the users in Azure AD (the admin user which is used for administration tasks) and then create the MDE tenant?
Mar 26 2021 05:45 AM
SolutionHi Jan,
As per the article, "When you use Azure Security Center to monitor your servers, a Microsoft Defender for Endpoint tenant is automatically created"
Please update if you have referred the section "Enabling the Microsoft Defender for Endpoint integration" in the article Using the Microsoft Defender for Endpoint license included with Azure Security Center | Microsoft Do...