Deploy Defender for Servers - Microsoft Defender for Cloud (2024)

  • Article

Defender for Servers in Microsoft Defender for Cloud brings threat detection and advanced defenses to your Windows and Linux machines that run in Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), and on-premises environments. This plan includes the integrated license for Microsoft Defender for Endpoint, security baselines and OS level assessments, vulnerability assessment scanning, file integrity monitoring (FIM), and more.

Microsoft Defender for Servers includes an automatic, native integration with Microsoft Defender for Endpoint. Learn more, Protect your endpoints with Defender for Cloud's integrated EDR solution: Microsoft Defender for Endpoint. With this integration enabled, you have access to the vulnerability findings from Microsoft Defender vulnerability management.

Defender for Servers offers two plan options with different levels of protection and their own cost. You can learn more about Defender for Cloud's pricing on the pricing page.

Prerequisites

  • You need a Microsoft Azure subscription. If you don't have an Azure subscription, you can sign up for a free subscription.

  • You must enable Microsoft Defender for Cloud on your Azure subscription.

  • Review the Defender for Servers deployment guide.

Enable the Defender for Servers plan

You can enable the Defender for Servers plan on an Azure subscription, AWS account, or GCP project, the Log Analytics workspace level, or enable the plan at the resource level.

Enable on an Azure subscription, AWS account, or GCP project

You can enable the Defender for Servers plan from the Environment settings page to protect all the machines in an Azure subscription, AWS account, or GCP project.

To enable the Defender for Servers plan:

  1. Sign in to the Azure portal.

  2. Search for and select Microsoft Defender for Cloud.

  3. In the Defender for Cloud menu, select Environment settings.

  4. Select the relevant Azure subscription, AWS account, or GCP project.

  5. On the Defender plans page, toggle the Servers switch to On.

After enabling the plan, you have the ability to configure the features of the plan to suit your needs. When you enable Defender for Servers on a subscription, it doesn't extend that coverage to an attached workspace. You need to enable Defender for Servers on the Log Analytics workspace level.

Select a Defender for Servers plan

When you enable the Defender for Servers plan, you're then given the option to select which plan - Plan 1 or Plan 2 - to enable. There are two plans you can choose from that offer different levels of protections for your resources.

Compare the available features provided by each plan.

To select a Defender for Servers plan:

  1. Sign in to the Azure portal.

  2. Search for and select Microsoft Defender for Cloud.

  3. In the Defender for Cloud menu, select Environment settings.

  4. Select the relevant Azure subscription, AWS account, or GCP project.

  5. Select Change plans.

  6. In the popup window, select Plan 2 or Plan 1.

  7. Select Confirm.

  8. Select Save.

After enabling the plan, you have the ability to configure the features of the plan to suit your needs.

Enable the plan at the Log Analytics workspace level

When you enable Defender for Servers on your subscription, the coverage provided by Defender for Servers isn't automatically extended to your Log Analytics workspaces. You need to enable Defender for Servers on each workspace. Defender for Servers on workspaces only supports Plan 2.

To enable Defender for Servers on the Log Analytics workspace:

  1. Sign in to the Azure portal.

  2. Search for and select Microsoft Defender for Cloud.

  3. In the Defender for Cloud menu, select Environment settings.

  4. Select the relevant workspace.

  5. Toggle the servers plan to On.

  6. Select Save.

By enabling Defender for Servers on a Log Analytics workspace, you aren't enabling all of the security protections available. You can also protect your Log Analytics workspaces with Foundational CSPM and SQL servers on machines.

Important

When you enable Defender for Servers on a workspace, all connected machines will automatically have Plan 2 enabled regardless of their connected subscription's settings.

Enable Defender for Servers at the resource level

To protect all of your existing and future resources, we recommend you enable Defender for Servers on your entire Azure subscription.

You can exclude specific resources or manage security configurations at a lower hierarchy level by enabling the Defender for Servers plan at the resource level. You can enable the plan on the resource level with REST API or at scale.

The supported resource types include:

  • Azure VMs.
  • On-premises with Azure Arc.
  • Azure Virtual Machine Scale Sets Flex.

Enable Defender for Servers at the resource level with REST API

The ability to enable or disable Defender for Servers at the resource level is available exclusively via REST API. Learn how to interact with the API to manage your Defender for Servers at the resource or subscription level.

After enabling the plan, you have the ability to configure the features of the plan to suit your needs.

Enable Defender for Servers at the resource level at scale

Use the following base script file to customize it for your specific needs.

  1. Download and save this file as a PowerShell file.

  2. Run the downloaded file.

  3. Set pricing by tag or by resource group.

  4. Follow the rest of the onscreen instructions.

After enabling the plan, you have the ability to configure the features of the plan to suit your needs.

Next steps

Configure Defender for Servers features.

Overview of Microsoft Defender for Servers.

Deploy Defender for Servers - Microsoft Defender for Cloud (2024)
Top Articles
A Complete Guide to B2b Credit Card Processing - BNG Payments
19 Trader Joe's foods we keep our freezer stocked with
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Aracelis Kilback

Last Updated:

Views: 6118

Rating: 4.3 / 5 (64 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Aracelis Kilback

Birthday: 1994-11-22

Address: Apt. 895 30151 Green Plain, Lake Mariela, RI 98141

Phone: +5992291857476

Job: Legal Officer

Hobby: LARPing, role-playing games, Slacklining, Reading, Inline skating, Brazilian jiu-jitsu, Dance

Introduction: My name is Aracelis Kilback, I am a nice, gentle, agreeable, joyous, attractive, combative, gifted person who loves writing and wants to share my knowledge and understanding with you.