Lesson 5 — Microsoft Defender for Servers
Microsoft Defender for Servers protects Windows and Linux machines across Azure, hybrid and multicloud environments. It combines Microsoft Defender for Endpoint integration, vulnerability assessment, agentless scanning, security recommendations and runtime threat detection.
Server protection is not simply a licence toggle. It depends on plan selection, machine onboarding, required extensions, supported operating systems, healthy telemetry and correct policy configuration.
This lesson explains Defender for Servers Plan 1 and Plan 2, Azure Arc, Defender for Endpoint integration, vulnerability management, agentless machine scanning, file integrity monitoring, just-in-time access, multicloud coverage and the operational checks needed to prove that every critical server is actually protected.

What you will learn
This lesson shows how Defender for Servers turns server telemetry into vulnerability insight, endpoint protection and cloud workload detections.
Defender for Servers architecture
Plan 1 and Plan 2
| Area | Plan 1 | Plan 2 |
|---|---|---|
| Primary purpose | Foundational endpoint-focused server protection | Broader advanced server security |
| Defender for Endpoint integration | Included for supported servers | Included for supported servers |
| Vulnerability capabilities | More limited | Expanded vulnerability and posture capabilities |
| Agentless scanning | Limited or unavailable depending on current service configuration | Broader support where available |
| Typical use | Cost-sensitive or lower-risk estates | Critical, regulated or high-risk servers |
Server onboarding workflow
Agent Foskett investigation: “The server looked healthy…”
Key takeaways
- Defender for Servers protects Windows and Linux machines across Azure, hybrid and multicloud environments.
- Plan 1 and Plan 2 provide different protection depth.
- Defender for Endpoint integration is central to endpoint detection and response.
- Azure Arc extends protection to supported non-Azure servers.
- Agentless scanning adds visibility without replacing every runtime capability.
- Vulnerability assessment must be monitored for coverage and freshness.
- Extension deployment alone does not prove healthy onboarding.
- Sensor health and telemetry must be validated continuously.
- Unsupported systems and exceptions must be documented.
- Coverage should be measured from each server upward.
Learning objectives
After completing this lesson, you should be able to explain how Defender for Servers is licensed, deployed, integrated and validated.
- Describe Plan 1 and Plan 2.
- Explain Defender for Endpoint integration.
- Understand Azure Arc onboarding.
- Explain agentless machine scanning.
- Review vulnerability assessment.
- Recognise hybrid and multicloud dependencies.
- Validate server telemetry and coverage.
What is Defender for Servers?
Microsoft Defender for Servers is the workload protection plan for Windows and Linux machines within Microsoft Defender for Cloud.
It combines cloud posture, endpoint protection, vulnerability insight and runtime threat detection.
Why servers need dedicated protection
Servers often host critical applications, privileged services, databases and sensitive business data.
A compromised server can become a persistence point, credential source or launch platform for lateral movement.
Supported environments
- Azure virtual machines
- Azure Arc-enabled servers
- Supported AWS EC2 instances
- Supported Google Cloud compute instances
- Selected hybrid and on-premises machines
Windows and Linux coverage
Defender for Servers supports both Windows and Linux, but exact feature support can vary by operating system, version and deployment method.
Defender for Endpoint integration
Microsoft Defender for Endpoint provides endpoint detection and response, behavioural analytics, investigation and response capabilities for supported servers.
EDR telemetry
Endpoint detection and response collects behavioural signals such as process execution, network activity, logons, files and persistence techniques.
Endpoint onboarding
A server must be correctly onboarded before endpoint telemetry and detections can be relied upon.
Onboarding method depends on operating system, platform and service configuration.
Sensor health
Sensor health is more important than extension presence.
A deployed extension can still fail to communicate, initialise or report current telemetry.
Azure Arc
Azure Arc enables supported non-Azure servers to appear as Azure resources and receive Defender for Servers capabilities.
Arc connection health
Disconnected or stale Arc agents can interrupt inventory, policy evaluation, extension deployment and protection coverage.
Direct onboarding scenarios
Some environments can use direct or alternative onboarding methods depending on current Defender for Cloud capabilities.
Designs should be checked against current Microsoft guidance.
Auto-provisioning
Auto-provisioning helps deploy required monitoring and security components to eligible machines.
Failures and exclusions must be reviewed.
Azure Policy
Azure Policy can standardise onboarding, extension deployment and configuration across subscriptions and management groups.
Agentless machine scanning
Agentless scanning can inspect supported machines without installing a traditional security agent inside the operating system.
What agentless scanning can reveal
- Installed software
- Known vulnerabilities
- Configuration weaknesses
- Secrets or sensitive artefacts where supported
- Exposure paths and attack surface
Agentless does not replace EDR
Agentless scanning provides assessment visibility, while EDR provides behavioural runtime telemetry and response.
They solve different security problems.
Vulnerability assessment
Vulnerability assessment identifies known weaknesses in operating systems and installed software.
Results should be prioritised using exposure, exploitability and business criticality.
Microsoft Defender Vulnerability Management
Defender Vulnerability Management can provide software inventory, vulnerability prioritisation and remediation insight for supported servers.
Vulnerability freshness
Stale vulnerability data can create false confidence.
Security teams should confirm assessment recency and machine health.
Security recommendations
Defender for Cloud generates recommendations for patching, configuration, endpoint coverage, exposure and hardening.
Secure score contribution
Server recommendations can influence Defender for Cloud secure score and help prioritise posture improvements.
Runtime threat detection
Defender for Servers can detect suspicious activity such as credential theft, malicious processes, persistence, command execution and network threats.
Fileless attack detection
Behavioural telemetry can help detect attacks that rely on PowerShell, WMI, memory execution and other fileless techniques.
Malware protection
Server protection should include healthy anti-malware or endpoint protection configuration appropriate to the operating system and workload.
Attack surface reduction
Attack surface reduction rules can reduce common exploitation paths on supported Windows systems.
They should be tested before broad enforcement.
File integrity monitoring
File integrity monitoring can help identify unauthorised changes to important files and registry areas where supported and configured.
Just-in-time VM access
Just-in-time access can reduce management-port exposure by limiting when approved inbound access is allowed.
Adaptive controls
Adaptive application controls and related recommendations can help identify expected software and unusual execution patterns where available.
Network exposure
Public IPs, open management ports and unrestricted network security rules increase server attack surface.
Identity exposure
Local administrators, service accounts, managed identities and cached credentials can make a server highly valuable to an attacker.
Privileged servers
Domain controllers, management servers, jump hosts and security infrastructure should receive enhanced monitoring and stricter change control.
Azure VM coverage
Azure virtual machines can inherit plan configuration from the subscription, but onboarding and telemetry still require validation.
AWS server coverage
AWS EC2 protection depends on a healthy cloud connector, correct permissions and supported onboarding components.
Google Cloud server coverage
Google Cloud compute protection similarly depends on connector health, permissions and supported machine configuration.
Hybrid server coverage
On-premises and hosted servers can be protected through supported hybrid onboarding methods such as Azure Arc.
Operating system support
Unsupported or end-of-life operating systems may not receive full protection.
They should be upgraded, isolated or covered by documented compensating controls.
Network requirements
Agents, extensions and sensors require access to supported service endpoints.
Proxy, firewall and TLS inspection settings can interrupt onboarding.
Permissions and roles
Correct Azure roles and cloud permissions are required to enable plans, deploy components and review security data.
Data residency and compliance
Organisations should review telemetry location, retention, regulatory obligations and operational access before deployment.
Performance considerations
Security components should be monitored for compatibility and performance, especially on high-throughput or legacy servers.
Pilot deployment
Begin with representative servers across operating systems, network zones and business workloads before scaling broadly.
Coverage dashboard
A useful server coverage dashboard should show plan status, onboarding state, sensor health, vulnerability freshness and telemetry recency.
Server coverage checklist
- Correct plan enabled
- Machine visible in inventory
- Supported operating system
- Endpoint onboarding healthy
- Extensions healthy
- Recent telemetry present
- Vulnerability assessment current
- Owner and criticality recorded
Validate alerts
Where safe and approved, use controlled testing to confirm that expected detections and response workflows operate correctly.
Validate integrations
Confirm that alerts flow into Defender XDR, Microsoft Sentinel or other approved security operations platforms as designed.
Common deployment gaps
- Plan enabled but server not onboarded
- Arc agent disconnected
- Endpoint sensor unhealthy
- Unsupported operating system
- Proxy blocking service endpoints
- Vulnerability data stale
- New subscription outside policy scope
What Agent Foskett checked
- Plan assignment
- Machine inventory
- Extension status
- Endpoint onboarding state
- Sensor health
- Last telemetry timestamp
- Network connectivity
- Policy compliance
- Other servers with the same failure
Operational lesson
Server protection must be measured by live telemetry and usable security outcomes, not by the presence of a portal object or extension.
Best practices
- Use policy-based onboarding.
- Protect critical servers with appropriate plan depth.
- Monitor Arc and sensor health.
- Track unsupported operating systems.
- Review vulnerability freshness.
- Test alert routing.
- Document exceptions and owners.
Related Agent Foskett resources
Continue learning
What is Microsoft Defender for Servers?
Microsoft Defender for Servers protects Windows and Linux machines across Azure, hybrid and multicloud environments using endpoint detection and response, vulnerability assessment, agentless scanning and cloud workload protection.
Microsoft Defender for Servers Lesson
This Agent Foskett lesson explains Defender for Servers Plan 1 and Plan 2, Defender for Endpoint integration, Azure Arc, agentless machine scanning, vulnerability management, runtime detection, server onboarding and protection validation.
