Covers Arc-enabled servers and Azure VMs in Defender for Cloud. Plan 1 brings integration with Defender for Endpoint; Plan 2 goes further with agentless scanning, file integrity monitoring and alerts from Defender for DNS.
Also called Defender for Servers.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Defender for Servers in context, with comparison tables and the common traps.
Terms in this definition
- Virtual machines
Infrastructure-as-a-service compute giving complete control of the operating system, making it a fit for lift-and-shift moves and for software relying on OS-level pieces like COM.
- Defender for Endpoint Plan 2
The top Defender for Endpoint licence, part of Microsoft 365 E5. On top of everything in Plan 1 it brings endpoint detection and response, automatic investigation and remediation, vulnerability management, threat analytics and in-depth file analysis.
- Agentless scanning
Defender for Cloud technique that inspects snapshots of VM disks for secrets, vulnerabilities and installed software, with nothing installed on the VM.
- File integrity monitoring
Capability in Defender for Servers Plan 2 that watches registry keys, configuration files and operating system files on Linux and Windows machines for changes.
- Microsoft Defender for DNS
Spots DNS tunnelling and data exfiltration, malicious resolvers, and domains used for phishing or command and control. This protection now ships within Defender for Servers Plan 2.
Related terms
- Amazon EC2
Amazon's virtual machine offering. Defender for Cloud can onboard EC2 instances automatically, installing Azure Arc and Defender components, when its AWS connector has Defender for Servers turned on.
- AWS connector (Defender for Cloud)
Connector linking Defender for Cloud to Amazon Web Services, finished by running a generated CloudFormation template on the AWS side. If Defender for Servers is enabled, it provisions Azure Arc onto EC2 instances automatically.
- CWPP
Short for Cloud Workload Protection Platform: guarding live workloads, including servers, containers, storage and databases, against attack. Defender for Cloud delivers this with its individual Defender plans, Defender for Servers and Defender for Containers being two examples.
- Defender for Servers Plan 1
The lower of the two Defender for Servers tiers: it includes Defender for Endpoint integration, giving EDR and anti-malware, plus vulnerability assessment through an agent. JIT access, FIM and agentless scanning come only with Plan 2.
- Defender for Servers Plan 2
Top Defender for Servers tier, which includes FIM, JIT VM access, agentless scanning and, from August 2023, Defender for DNS alerts. You turn it on per subscription or per Log Analytics workspace.
- Direct onboarding
A way to bring servers outside Azure into Defender for Cloud via Defender for Endpoint, with no Azure Arc needed. Such servers get the Plan 1 feature set of Defender for Servers; on Plan 2 the only extra is premium vulnerability management.
- Integrated vulnerability assessment
A Qualys-powered extension for Defender for Servers, now retired and replaced by Defender Vulnerability Management. It scanned Arc machines and Windows and Linux Azure VMs, though not scale set instances.
- Just-in-time VM access
Defender for Servers capability that keeps management ports closed through deny rules in an NSG or Azure Firewall, then opens them temporarily for the requester's IP, by default for at most 3 hours. VMs lacking either control aren't supported.