When the actual usage of Security Center exceeds the subscription quota, elastic protection is automatically enabled and billed on a pay-as-you-go basis to ensure uninterrupted security. This topic describes the usage recommendations, impact of enabling elastic protection, and how to enable it.
Usage notes
Elastic protection is a pay-as-you-go mechanism provided by Security Center. When the actual usage exceeds the subscription quota, the system automatically enables elastic protection and incurs additional fees.
Usage recommendations
Determine whether to enable elastic protection based on your business requirements:
-
Recommended: Your business has significant traffic fluctuations, an uncertain attack surface, or strict security compliance requirements for continuous coverage.
-
Optional: Your subscription quota is sufficient for long-term use, budget control is strict, and your business scale is stable.
Supported features
-
Features that can be enabled together: Protected Servers (edition service), Agentic EDR, Anti-Ransomware, and Agentic Cloud Platform Configuration Check.
-
Feature that must be enabled separately: Attack Management.
Impact
-
Elastic protection applies only to Subscription. Pay-as-you-go services purchased separately are not affected.
-
Usage that exceeds the subscription quota is billed based on the actual usage on a pay-as-you-go basis. Bills are generated on the next day. For more information about billing, see Billing overview.
Enablement method
When you purchase the corresponding subscription service, elastic protection is enabled by default. You can also manually enable it as described in the following sections.
Manually enable elastic protection
Different feature modules have different entry points for enabling elastic protection. Select the corresponding operation based on the module you use.
Enable together
Supported features
Protected Servers (edition service), Agentic EDR, Anti-Ransomware, and Agentic Cloud Platform Configuration Check.
Procedure
-
Go to the Security Center console - Assets - Asset Overview. In the upper-left corner of the page, select the region where the assets to be protected reside: Chinese Mainland or Outside Chinese Mainland.
-
On the Overview page, above the Subscription section, turn on the Elastic Protection switch.
Enable separately
Supported features
Attack Management
Procedure
Attack Management
-
Log on to the Security Center console.
-
On the Overview page, in the Attack Surface Management section, turn on the Full Protection switch.
FAQ
-
How do I view the usage after elastic protection is enabled?
On the Overview page, above the Subscription section, view the usage statistics (used quota/subscription quota) of each module.
-
Where is the elastic protection switch?
Different feature modules have different entry points for the elastic protection switch.
-
Protected Servers (edition service), Agentic EDR, Anti-Ransomware, and Agentic Cloud Platform Configuration Check share the same switch. The switch is located above the Subscription section on the Overview page and is labeled Elastic Protection.
-
Attack Management has a separate switch. The switch is located in the Attack Surface Management section on the Overview page and is labeled Full Protection.
-
-
Why was elastic protection automatically enabled?
For features that support elastic protection, Security Center automatically enables elastic protection after you purchase the corresponding subscription service. No manual operation is required. If you want to disable elastic protection, see Disable elastic protection.