Share via

Defender for Cloud P2 500MB free data benefit not applying to SecurityEvents in Sentinel workspace

Ipmando 20 Reputation points
2026-02-11T11:10:59.8333333+00:00

Hi!

Have Microsoft Defender for Cloud Plan 2 enabled for approximately 1 week on multiple servers in our subscription. We are expecting the 500MB/day free data ingestion benefit per server to be applied to our Log Analytics/Sentinel workspace, however all SecurityEvent data is showing as fully billable with no free tier credit applied.

Environment:

Defender for Cloud Plan 2 confirmed on servers (hybrid azure arc)

Log Analytics workspace used by Microsoft Sentinel

MMA (Log Analytics Agent) is disabled — on deprecation path

AMA (Azure Monitor Agent) in use via DCRs created through the Sentinel "Windows Security Events via AMA" data connector

Sentinel workspace is the only target

Observed behaviour via KQL query against Usage table:

SecurityEvents ingesting at approximately 1gb/day

All data showing as IsBillable = true

FreeGB = 0 — no free benefit being applied

Issue persists for approximately 1 week

Anyone else had this issue, that everything seems fine but not getting 500mb via DfS P2 for the specific logs ?

Microsoft Security | Microsoft Sentinel
{count} votes

Answer accepted by question author
  1. Rukmini 29,050 Reputation points Microsoft External Staff Moderator
    2026-02-11T12:24:03.24+00:00

    Hello Ipmando

    Only security data gathered by Defender for Cloud's auto-provisioned AMA data collection rules is eligible for the 500 MB/day Defender for Servers Plan 2 ingestion benefit. The Microsoft Sentinel "Windows Security Events via AMA" connector (custom DCR) is used in your setup to gather Security Events. This method is used to ingest data, which is fully billable and handled like regular Log Analytics ingestion. Consequently: IsBillable = true FreeGB is equal to zero. is expected behavior.

    Security Events must be gathered via Defender for Cloud auto-provisioning rather than the Sentinel AMA connection DCR in order to qualify for the 500 MB/day incentive.

    As updated by you, In Sentinel subscription, under Sentinel log analytics workspace set Enviorment Settings -> Data Collection to Common.

    I didn't create its own DCR's but it enabled ingestion benefits to my DCR's made via Sentinel Data Connectors.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.