Blanket onboarding with default service attach turned a free control plane into an unbudgeted six figure annual line in roughly 18 of 30 estates
The control plane genuinely is free. What attaches to it by default is not, and the difference between those two facts arrives as a six figure line nobody put in a budget.
Prepared by Redress Compliance · August 17, 2026 · Microsoft advisory. 30 to 40 Microsoft EA and Azure reviews, 2024 to 2025.
Executive summary
Blanket onboarding with default service attach produced an unbudgeted six figure annual line in roughly 18 of 30 estates. Led by Monitor ingestion and Defender defaults that nobody scoped before the rollout began.
Per server Defender and Monitor charges on Arc connected machines grew two to three times faster than the estates forecast. Because the forecast was built on server count and the charge is driven by what each server emits.
Arc enabled ESU billing was 20 to 40 percent cheaper than classic ESU agreements. In the estates that compared both paths, and mid migration estates stop paying for each server the month it is decommissioned.
Counting Arc attached consumption toward MACC retired commits three to six months earlier. A benefit most estates leave unclaimed because the Arc line and the commitment are managed by different people.
Free control plane, priced attachments
Arc separates cleanly into what costs nothing and what does. Most of the surprise comes from the second column being on by default.
| Element | Cost | Driven by |
|---|---|---|
| The Arc control plane | Free | Nothing, which is why it gets rolled out broadly |
| Monitor ingestion | Charged | What each server emits, not how many there are |
| Defender per server | Charged | Every onboarded machine, by default |
| Arc enabled ESU | Charged, 20 to 40 percent below classic | Per server, per month while running |
The free control plane is what makes blanket onboarding feel safe, and blanket onboarding is what makes the attachments expensive. A team evaluating Arc correctly concludes that the management layer costs nothing, and reasonably decides to onboard broadly. Nothing in that decision prompts a review of which services attach to each onboarded machine, and the defaults do the rest. The cost is not hidden; it is simply attached to a decision that was framed as free.
The forecast counted servers. The bill counts what they emit
Across roughly 30 to 40 Microsoft EA and Azure reviews advised between 2024 and 2025, Azure Arc appeared as an unplanned cost line more often than a planned one. In roughly 18 of the 30 plus estates reviewed, blanket onboarding with default service attach turned a free control plane into an unbudgeted six figure annual line, led by Monitor ingestion and Defender defaults nobody scoped.
The forecasting error underneath it is specific and repeatable. Per server Defender and Monitor charges on Arc connected machines grew two to three times faster than the estates forecast, because the forecast was built on server count while the charge is driven by what each server emits. Server count is stable and knowable; log volume is neither, and it rises with every agent, every diagnostic setting, and every well intentioned observability improvement. A model built on the first variable will always underestimate a bill driven by the second.
Two genuine benefits sit alongside the problem and both are commonly missed. Arc enabled ESU billing was 20 to 40 percent cheaper than classic ESU agreements in the estates that compared both paths, and the mechanism matters as much as the number: estates mid migration stop paying for each server the month it is decommissioned, which routinely beats an annual commitment by 20 to 40 percent. For a shrinking estate, paying monthly for what is still running is structurally better than committing annually for what existed at signature.
The second is a commitment benefit. Buyers who counted Arc attached consumption toward their MACC retired commits three to six months earlier, which is straightforward value left on the table because the Arc line and the Azure commitment are usually managed by different people. Scope service attach per machine group rather than globally, forecast Monitor on emitted volume rather than server count, compare the Arc ESU path against the classic agreement if you are mid migration, and make sure the consumption is counted toward the commit. The commitment reshape question sits in the MACC brief, the hybrid entitlement in the hybrid playbook, and the library in the Microsoft practice.
- Usage exports analysed: inactive accounts, plan right sizing, per user reassignment
- Your renewal quote benchmarked against real closed Microsoft deals
- Every risky clause flagged with the exact quote, the page, and the replacement language
The Microsoft EA renewal playbook
The renewal moves, the EA framework, the SKU framework, and the buyer side moves across the full Microsoft estate.
Get the brief →Controlling the attach
- Scope service attach per machine group, not globally, because blanket onboarding with defaults is what produced the six figure line in 18 of 30 estates.
- Forecast Monitor on emitted log volume, not server count, since the charge follows what each machine emits and that is the variable that grew 2 to 3 times faster than expected.
- Review Defender defaults before onboarding, rather than after the first full month of billing arrives.
- Compare the Arc ESU path against a classic ESU agreement if you are mid migration, where it ran 20 to 40 percent cheaper.
- Use the monthly shape deliberately, since stopping payment the month a server is decommissioned is what beats the annual commitment for a shrinking estate.
- Count Arc attached consumption toward the MACC, which retired commits three to six months earlier for the buyers who did.
What the Azure reviews showed, 2024 to 2025
Across roughly 30 to 40 Microsoft EA and Azure reviews:
Estates where blanket onboarding with default service attach turned a free control plane into an unplanned annual line, led by Monitor ingestion and Defender defaults.
How far Arc enabled ESU billing came in below classic ESU agreements in the estates that compared both paths.
Per server Defender and Monitor charges on Arc connected machines grew two to three times faster than the estates forecast, because the forecast counted servers and the bill counts emitted volume.
Estates mid migration stop paying for each server the month it is decommissioned, and buyers who counted Arc attached consumption toward their MACC retired commits three to six months earlier.
Watch the briefing · 3:585 Tips for Your Microsoft NegotiationWhich lines are genuinely free, and what attaches to them by default.
Your first five moves
- Audit which services are attached to every Arc onboarded machine today, before adding any more.
- Rebuild the Monitor forecast on emitted volume, not on server count.
- Set Defender attach per machine group rather than accepting the global default.
- Model Arc ESU against classic ESU if the estate is shrinking mid migration.
- Confirm Arc consumption counts toward the MACC. The Microsoft practice scopes the attach with you.
Frequently asked questions
Is Azure Arc free?
The control plane is. Monitor ingestion and Defender charges on Arc connected machines are not, and they attach by default, which is how a free management layer produced an unbudgeted six figure annual line in roughly 18 of 30 estates.
Why do the costs surprise people?
Because the decision was framed as free. A team correctly concludes the management layer costs nothing and onboards broadly, and nothing in that decision prompts a review of which services attach to each machine.
Why did the forecasts miss by so much?
Charges grew two to three times faster than forecast because the forecast was built on server count while the charge is driven by what each server emits. Server count is stable; log volume is not.
What drives Monitor cost?
Emitted volume. It rises with every agent, every diagnostic setting, and every observability improvement, none of which appear in a model built on how many machines exist.
Is Arc enabled ESU cheaper?
It was 20 to 40 percent cheaper than classic ESU agreements in the estates that compared both paths, and the shape matters: you stop paying for each server the month it is decommissioned.
Why does that suit a shrinking estate?
Because an annual commitment prices what existed at signature while monthly per server billing prices what is still running. For an estate mid migration the difference compounds every month.
Does Arc consumption count toward MACC?
It can, and buyers who counted it retired commits three to six months earlier. It is commonly missed because the Arc line and the Azure commitment are managed by different people.
How should service attach be scoped?
Per machine group rather than globally. Blanket onboarding with default attach is precisely what produced the unbudgeted line, and per group scoping is the whole control.
What should we check first?
Which services are attached to every Arc onboarded machine today. That audit tells you what the current run rate is actually paying for, before anything more is onboarded.
Is the cost hidden?
No, and that is worth being clear about. It is fully visible in billing. It is simply attached to a decision that was correctly described as free, so nobody went looking for it.