Top Defender for Servers tier, which includes FIM, JIT VM access, agentless scanning and, from August 2023, Defender for DNS alerts. You turn it on per subscription or per Log Analytics workspace.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Defender for Servers Plan 2 in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Defender for Servers
Covers Arc-enabled servers and Azure VMs in Defender for Cloud. Plan 1 brings integration with Defender for Endpoint; Plan 2 goes further with agentless scanning, file integrity monitoring and alerts from Defender for DNS.
- Archive
Offline access tier for blobs, cheapest to store yet dearest to access. Reading a blob means rehydrating it first, which can take as long as 15 hours.
- File integrity monitoring
Capability in Defender for Servers Plan 2 that watches registry keys, configuration files and operating system files on Linux and Windows machines for changes.
- Just-in-time VM access
Defender for Servers capability that keeps management ports closed through deny rules in an NSG or Azure Firewall, then opens them temporarily for the requester's IP, by default for at most 3 hours. VMs lacking either control aren't supported.
- Agentless scanning
Defender for Cloud technique that inspects snapshots of VM disks for secrets, vulnerabilities and installed software, with nothing installed on the VM.
- Microsoft Defender for DNS
Spots DNS tunnelling and data exfiltration, malicious resolvers, and domains used for phishing or command and control. This protection now ships within Defender for Servers Plan 2.
- TURN
If a direct link can't be made, RDP Shortpath for Windows 365 relays UDP traffic via Microsoft servers on port 3478 instead.
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
Related terms
- Agentless malware scanning
Snapshot-based malware check for VM disks that runs Microsoft Defender Antivirus engines with no agent installed. It comes with Defender for Servers Plan 2, not with Defender CSPM by itself.
- Machine secrets scanning
Defender for Cloud check, done without agents, that searches VM disk snapshots for secrets in plain text such as tokens, SSH private keys and connection strings. It requires Defender for Servers Plan 2 or Defender CSPM.
- Microsoft Defender Vulnerability Management add-on
Licence giving devices premium MDVM features, such as firmware and certificate assessment, security baselines and blocking of vulnerable apps. Servers covered by Defender for Servers Plan 2 have these already.