Agent Foskett Academy • Microsoft Defender for Cloud • Module 1 • Lesson 5

Lesson 5 — Microsoft Defender for Servers

Microsoft Defender for Servers protects Windows and Linux machines across Azure, hybrid and multicloud environments. It combines Microsoft Defender for Endpoint integration, vulnerability assessment, agentless scanning, security recommendations and runtime threat detection.

Server protection is not simply a licence toggle. It depends on plan selection, machine onboarding, required extensions, supported operating systems, healthy telemetry and correct policy configuration.

This lesson explains Defender for Servers Plan 1 and Plan 2, Azure Arc, Defender for Endpoint integration, vulnerability management, agentless machine scanning, file integrity monitoring, just-in-time access, multicloud coverage and the operational checks needed to prove that every critical server is actually protected.

A server is only protected when its plan, onboarding, components and telemetry are all working together.
Agent Foskett Microsoft Defender for Servers lesson
What you will learn

This lesson shows how Defender for Servers turns server telemetry into vulnerability insight, endpoint protection and cloud workload detections.

Plan 1 and Plan 2
Endpoint integration
Vulnerability and agentless scanning
Hybrid and multicloud coverage

Defender for Servers architecture

Windows and Linux machines ↓ Azure VM, Azure Arc or multicloud connection ↓ Defender for Servers plan enabled ↓ Defender for Endpoint and supporting components onboard ↓ Vulnerability, configuration and runtime telemetry collected ↓ Recommendations, alerts and incidents ↓ Investigation and remediation

Plan 1 and Plan 2

AreaPlan 1Plan 2
Primary purposeFoundational endpoint-focused server protectionBroader advanced server security
Defender for Endpoint integrationIncluded for supported serversIncluded for supported servers
Vulnerability capabilitiesMore limitedExpanded vulnerability and posture capabilities
Agentless scanningLimited or unavailable depending on current service configurationBroader support where available
Typical useCost-sensitive or lower-risk estatesCritical, regulated or high-risk servers
Always verify current Microsoft feature inclusions before making a licensing decision.

Server onboarding workflow

Identify server estate ↓ Classify business criticality ↓ Enable Defender for Servers ↓ Connect Azure, Arc, AWS or Google Cloud machines ↓ Deploy required extensions and integrations ↓ Confirm endpoint onboarding ↓ Validate telemetry and recommendations ↓ Test alerting and response workflow

Agent Foskett investigation: “The server looked healthy…”

A production server showed as running ↓ Patch status looked normal ↓ Operations believed it was protected ↓ An attacker established persistence ↓ No endpoint alert appeared ↓ Agent Foskett checked Defender for Cloud ↓ The server existed in inventory ↓ But Microsoft Defender for Endpoint onboarding had failed ↓ The extension was present ↓ The sensor was not reporting ↓ The machine had no current endpoint telemetry ↓ The issue had been hidden by a high-level green status ↓ Onboarding was repaired ↓ Telemetry returned ↓ Coverage reporting was changed to validate sensor health, not just extension deployment
The server was visible, but it was not reporting the telemetry needed to protect it.

Key takeaways

  • Defender for Servers protects Windows and Linux machines across Azure, hybrid and multicloud environments.
  • Plan 1 and Plan 2 provide different protection depth.
  • Defender for Endpoint integration is central to endpoint detection and response.
  • Azure Arc extends protection to supported non-Azure servers.
  • Agentless scanning adds visibility without replacing every runtime capability.
  • Vulnerability assessment must be monitored for coverage and freshness.
  • Extension deployment alone does not prove healthy onboarding.
  • Sensor health and telemetry must be validated continuously.
  • Unsupported systems and exceptions must be documented.
  • Coverage should be measured from each server upward.

Learning objectives

After completing this lesson, you should be able to explain how Defender for Servers is licensed, deployed, integrated and validated.

  • Describe Plan 1 and Plan 2.
  • Explain Defender for Endpoint integration.
  • Understand Azure Arc onboarding.
  • Explain agentless machine scanning.
  • Review vulnerability assessment.
  • Recognise hybrid and multicloud dependencies.
  • Validate server telemetry and coverage.

What is Defender for Servers?

Microsoft Defender for Servers is the workload protection plan for Windows and Linux machines within Microsoft Defender for Cloud.

It combines cloud posture, endpoint protection, vulnerability insight and runtime threat detection.

Why servers need dedicated protection

Servers often host critical applications, privileged services, databases and sensitive business data.

A compromised server can become a persistence point, credential source or launch platform for lateral movement.

Supported environments

  • Azure virtual machines
  • Azure Arc-enabled servers
  • Supported AWS EC2 instances
  • Supported Google Cloud compute instances
  • Selected hybrid and on-premises machines

Windows and Linux coverage

Defender for Servers supports both Windows and Linux, but exact feature support can vary by operating system, version and deployment method.

Defender for Endpoint integration

Microsoft Defender for Endpoint provides endpoint detection and response, behavioural analytics, investigation and response capabilities for supported servers.

EDR telemetry

Endpoint detection and response collects behavioural signals such as process execution, network activity, logons, files and persistence techniques.

Endpoint onboarding

A server must be correctly onboarded before endpoint telemetry and detections can be relied upon.

Onboarding method depends on operating system, platform and service configuration.

Sensor health

Sensor health is more important than extension presence.

A deployed extension can still fail to communicate, initialise or report current telemetry.

Azure Arc

Azure Arc enables supported non-Azure servers to appear as Azure resources and receive Defender for Servers capabilities.

Arc connection health

Disconnected or stale Arc agents can interrupt inventory, policy evaluation, extension deployment and protection coverage.

Direct onboarding scenarios

Some environments can use direct or alternative onboarding methods depending on current Defender for Cloud capabilities.

Designs should be checked against current Microsoft guidance.

Auto-provisioning

Auto-provisioning helps deploy required monitoring and security components to eligible machines.

Failures and exclusions must be reviewed.

Azure Policy

Azure Policy can standardise onboarding, extension deployment and configuration across subscriptions and management groups.

Agentless machine scanning

Agentless scanning can inspect supported machines without installing a traditional security agent inside the operating system.

What agentless scanning can reveal

  • Installed software
  • Known vulnerabilities
  • Configuration weaknesses
  • Secrets or sensitive artefacts where supported
  • Exposure paths and attack surface

Agentless does not replace EDR

Agentless scanning provides assessment visibility, while EDR provides behavioural runtime telemetry and response.

They solve different security problems.

Vulnerability assessment

Vulnerability assessment identifies known weaknesses in operating systems and installed software.

Results should be prioritised using exposure, exploitability and business criticality.

Microsoft Defender Vulnerability Management

Defender Vulnerability Management can provide software inventory, vulnerability prioritisation and remediation insight for supported servers.

Vulnerability freshness

Stale vulnerability data can create false confidence.

Security teams should confirm assessment recency and machine health.

Security recommendations

Defender for Cloud generates recommendations for patching, configuration, endpoint coverage, exposure and hardening.

Secure score contribution

Server recommendations can influence Defender for Cloud secure score and help prioritise posture improvements.

Runtime threat detection

Defender for Servers can detect suspicious activity such as credential theft, malicious processes, persistence, command execution and network threats.

Fileless attack detection

Behavioural telemetry can help detect attacks that rely on PowerShell, WMI, memory execution and other fileless techniques.

Malware protection

Server protection should include healthy anti-malware or endpoint protection configuration appropriate to the operating system and workload.

Attack surface reduction

Attack surface reduction rules can reduce common exploitation paths on supported Windows systems.

They should be tested before broad enforcement.

File integrity monitoring

File integrity monitoring can help identify unauthorised changes to important files and registry areas where supported and configured.

Just-in-time VM access

Just-in-time access can reduce management-port exposure by limiting when approved inbound access is allowed.

Adaptive controls

Adaptive application controls and related recommendations can help identify expected software and unusual execution patterns where available.

Network exposure

Public IPs, open management ports and unrestricted network security rules increase server attack surface.

Identity exposure

Local administrators, service accounts, managed identities and cached credentials can make a server highly valuable to an attacker.

Privileged servers

Domain controllers, management servers, jump hosts and security infrastructure should receive enhanced monitoring and stricter change control.

Azure VM coverage

Azure virtual machines can inherit plan configuration from the subscription, but onboarding and telemetry still require validation.

AWS server coverage

AWS EC2 protection depends on a healthy cloud connector, correct permissions and supported onboarding components.

Google Cloud server coverage

Google Cloud compute protection similarly depends on connector health, permissions and supported machine configuration.

Hybrid server coverage

On-premises and hosted servers can be protected through supported hybrid onboarding methods such as Azure Arc.

Operating system support

Unsupported or end-of-life operating systems may not receive full protection.

They should be upgraded, isolated or covered by documented compensating controls.

Network requirements

Agents, extensions and sensors require access to supported service endpoints.

Proxy, firewall and TLS inspection settings can interrupt onboarding.

Permissions and roles

Correct Azure roles and cloud permissions are required to enable plans, deploy components and review security data.

Data residency and compliance

Organisations should review telemetry location, retention, regulatory obligations and operational access before deployment.

Performance considerations

Security components should be monitored for compatibility and performance, especially on high-throughput or legacy servers.

Pilot deployment

Begin with representative servers across operating systems, network zones and business workloads before scaling broadly.

Coverage dashboard

A useful server coverage dashboard should show plan status, onboarding state, sensor health, vulnerability freshness and telemetry recency.

Server coverage checklist

  • Correct plan enabled
  • Machine visible in inventory
  • Supported operating system
  • Endpoint onboarding healthy
  • Extensions healthy
  • Recent telemetry present
  • Vulnerability assessment current
  • Owner and criticality recorded

Validate alerts

Where safe and approved, use controlled testing to confirm that expected detections and response workflows operate correctly.

Validate integrations

Confirm that alerts flow into Defender XDR, Microsoft Sentinel or other approved security operations platforms as designed.

Common deployment gaps

  • Plan enabled but server not onboarded
  • Arc agent disconnected
  • Endpoint sensor unhealthy
  • Unsupported operating system
  • Proxy blocking service endpoints
  • Vulnerability data stale
  • New subscription outside policy scope

What Agent Foskett checked

  • Plan assignment
  • Machine inventory
  • Extension status
  • Endpoint onboarding state
  • Sensor health
  • Last telemetry timestamp
  • Network connectivity
  • Policy compliance
  • Other servers with the same failure

Operational lesson

Server protection must be measured by live telemetry and usable security outcomes, not by the presence of a portal object or extension.

Best practices

  • Use policy-based onboarding.
  • Protect critical servers with appropriate plan depth.
  • Monitor Arc and sensor health.
  • Track unsupported operating systems.
  • Review vulnerability freshness.
  • Test alert routing.
  • Document exceptions and owners.

Continue learning

Continue Module 1 with a detailed look at Microsoft Defender for Storage and how cloud data services are protected.

What is Microsoft Defender for Servers?

Microsoft Defender for Servers protects Windows and Linux machines across Azure, hybrid and multicloud environments using endpoint detection and response, vulnerability assessment, agentless scanning and cloud workload protection.

Microsoft Defender for Servers Lesson

This Agent Foskett lesson explains Defender for Servers Plan 1 and Plan 2, Defender for Endpoint integration, Azure Arc, agentless machine scanning, vulnerability management, runtime detection, server onboarding and protection validation.