Onboard non-Azure machines with Defender for Endpoint - Microsoft Defender for Cloud (2024)

  • Article

Defender for Cloud allows you to directly onboard your non-Azure servers by deploying the Defender for Endpoint agent. This provides protection for both your cloud and non-cloud assets under a single, unified offering.

This tenant-level setting allows you to automatically and natively onboard any non-Azure server running Defender for Endpoint to Defender for Cloud, without any extra agent deployments. This onboarding path is ideal for customers with mixed and hybrid server estate who wish to consolidate server protection under Defender for Servers.

Availability

AspectDetails
Release stateGA
Supported operating systemsAll Windows and Linux Server operating systems supported by Defender for Endpoint
Required roles and permissionsTo manage this setting, you need Subscription Owner (on the chosen subscription), and Microsoft Entra Global Administrator or Microsoft Entra Security Administrator
EnvironmentsOn-premises servers
Multicloud VMs – limited support (see limitations section)
Supported plansDefender for Servers P1
Defender for Servers P2 – limited features (see limitations section)

How it works

Direct onboarding is a seamless integration between Defender for Endpoint and Defender for Cloud that doesn’t require extra software deployment on your servers. Once enabled, it also shows your non-Azure server devices onboarded to Defender for Endpoint in Defender for Cloud, under a designated Azure Subscription you configure (in addition to their regular representation in the Microsoft Defender Portal). The Azure Subscription is used for licensing, billing, alerts, and security insights but doesn't provide server management capabilities such as Azure Policy, Extensions, or Guest configuration. To enable server management capabilities, refer to the deployment of Azure Arc.

Enabling direct onboarding

Enabling direct onboarding is an opt-in setting at the tenant level. It affects both existing and new servers onboarded to Defender for Endpoint in the same Microsoft Entra tenant. Shortly after you enable this setting, your server devices will show under the designated subscription. Alerts, software inventory, and vulnerability data are integrated with Defender for Cloud, in a similar way to how it works with Azure VMs.

Before you begin:

  • Make sure you have the required permissions
  • If you have a Microsoft Defender for Endpoint for Servers license on your tenant, make sure to indicate it in Defender for Cloud
  • Review the limitations section

Enabling in the Defender for Cloud portal

  1. Go to Defender for Cloud > Environment Settings > Direct onboarding.
  2. Switch the Direct onboarding toggle to On.
  3. Select the subscription you would like to use for servers onboarded directly with Defender for Endpoint.
  4. Select Save.

Onboard non-Azure machines with Defender for Endpoint - Microsoft Defender for Cloud (1)

You now successfully enabled direct onboarding on your tenant. After you enable it for the first time, it might take up to 24 hours to see your non-Azure servers in your designated subscription.

Deploying Defender for Endpoint on your servers

Deploying the Defender for Endpoint agent on your on-premises Windows and Linux servers is the same whether you use direct onboarding or not. Refer to the Defender for Endpoint onboarding guide for further instructions.

Current limitations

  • Plan support: Direct onboarding provides access to all Defender for Servers Plan 1 features. However, certain features in Plan 2 still require the deployment of the Azure Monitor Agent, which is only available with Azure Arc on non-Azure machines. If you enable Plan 2 on your designated subscription, machines onboarded directly with Defender for Endpoint have access to all Defender for Servers Plan 1 features and the Defender Vulnerability Management Addon features included in Plan 2.

  • Multi-cloud support: You can directly onboard VMs in AWS and GCP using the Defender for Endpoint agent. However, if you plan to simultaneously connect your AWS or GCP account to Defender for Servers using multicloud connectors, it's currently still recommended to deploy Azure Arc.

  • Simultaneous onboarding limited support: For servers simultaneously onboarded using multiple methods (for example, direct onboarding combined with Log Analytics workspace-based onboarding), Defender for Cloud makes every effort to correlate them into a single device representation. However, devices using older versions of Defender for Endpoint might face certain limitations. In some instances, this could result in overcharges. We generally advise using the latest agent version. Specifically, for this limitation, ensure your Defender for Endpoint agent versions meet or exceed these minimum versions:

    Operating SystemMinimum agent version
    Windows 201910.8555
    Windows 2012 R2, 2016 (modern, unified agent)10.8560
    Linux30.101.23052.009

Next steps

This page showed you how to add your non-Azure machines to Microsoft Defender for Cloud. To monitor their status, use the inventory tools as explained in the following page:

  • Explore and manage your resources with asset inventory
Onboard non-Azure machines with Defender for Endpoint - Microsoft Defender for Cloud (2024)
Top Articles
De hypotheek aflossen: Over deze dingen moet je even nadenken - De Budgetman.nl
De hypotheek van Financial Chipmunk
WALB Locker Room Report Week 5 2024
neither of the twins was arrested,传说中的800句记7000词
Srtc Tifton Ga
Knoxville Tennessee White Pages
Kem Minnick Playboy
Wordscapes Level 6030
Pangphip Application
Affidea ExpressCare - Affidea Ireland
Imbigswoo
Revitalising marine ecosystems: D-Shape’s innovative 3D-printed reef restoration solution - StartmeupHK
Signs Of a Troubled TIPM
10 Free Employee Handbook Templates in Word & ClickUp
Bowlero (BOWL) Earnings Date and Reports 2024
Craigslist Edmond Oklahoma
Harem In Another World F95
Trivago Sf
Cvs El Salido
Timeforce Choctaw
Why do rebates take so long to process?
Canvasdiscount Black Friday Deals
Mega Personal St Louis
Marion City Wide Garage Sale 2023
Wat is een hickmann?
Weathervane Broken Monorail
Kuttymovies. Com
Worthington Industries Red Jacket
Plasma Donation Racine Wi
Perry Inhofe Mansion
County Cricket Championship, day one - scores, radio commentary & live text
The value of R in SI units is _____?
Microsoftlicentiespecialist.nl - Microcenter - ICT voor het MKB
Tgh Imaging Powered By Tower Wesley Chapel Photos
Bismarck Mandan Mugshots
How to Draw a Sailboat: 7 Steps (with Pictures) - wikiHow
Nba Props Covers
Flipper Zero Delivery Time
Thor Majestic 23A Floor Plan
Promo Code Blackout Bingo 2023
Here's Everything You Need to Know About Baby Ariel
Tropical Smoothie Address
Lesly Center Tiraj Rapid
Stoughton Commuter Rail Schedule
Identogo Manahawkin
Great Clips Virginia Center Commons
Craigslist Indpls Free
March 2023 Wincalendar
Ret Paladin Phase 2 Bis Wotlk
Bones And All Showtimes Near Emagine Canton
Duffield Regional Jail Mugshots 2023
Latest Posts
Article information

Author: Francesca Jacobs Ret

Last Updated:

Views: 6087

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Francesca Jacobs Ret

Birthday: 1996-12-09

Address: Apt. 141 1406 Mitch Summit, New Teganshire, UT 82655-0699

Phone: +2296092334654

Job: Technology Architect

Hobby: Snowboarding, Scouting, Foreign language learning, Dowsing, Baton twirling, Sculpting, Cabaret

Introduction: My name is Francesca Jacobs Ret, I am a innocent, super, beautiful, charming, lucky, gentle, clever person who loves writing and wants to share my knowledge and understanding with you.