Lesson 4 — Microsoft Defender Plans Overview
Microsoft Defender plans add workload-specific security capabilities to Microsoft Defender for Cloud. They determine which resources receive runtime threat protection, vulnerability assessment, malware scanning, endpoint integration and other advanced capabilities.
Defender for Cloud can be visible in a tenant without every workload being protected. Coverage depends on which plans are enabled, where they are enabled, which resources are supported and whether the required components are correctly deployed.
This lesson explains plan scope, subscription coverage, multicloud onboarding, Defender for Servers Plan 1 and Plan 2, feature validation, cost governance and the operational checks needed to prove that protection actually exists.

What you will learn
This lesson shows how Defender plans translate cloud security requirements into measurable workload coverage.
The Defender plan model
Platform versus plan
| Area | Defender for Cloud platform | Defender plan |
|---|---|---|
| Purpose | Central posture and workload security management | Protection for a specific workload category |
| Example | Recommendations, inventory and alerts | Defender for Servers or Defender for Storage |
| Scope | Connected cloud environment | Selected subscriptions, accounts, projects or resources |
| Cost | Foundational capabilities may be available without paid workload plans | Paid according to plan and protected usage |
Defender for Servers Plan 1 and Plan 2
| Area | Plan 1 | Plan 2 |
|---|---|---|
| Primary use | Foundational endpoint-focused server protection | Broader advanced server protection |
| Endpoint integration | Supported | Supported |
| Advanced capabilities | More limited | Expanded |
| Typical scope | Lower-risk or cost-sensitive server estates | Critical, regulated or higher-risk server estates |
Plan scope workflow
Cost governance model
Agent Foskett investigation: “The protection was never enabled…”
Key takeaways
- Defender plans provide workload-specific protection within Defender for Cloud.
- The platform and paid Defender plans are not the same thing.
- Plan selection should follow workload inventory, risk and criticality.
- Subscription-level enablement does not guarantee resource-level coverage.
- Policy and auto-provisioning help reduce configuration drift.
- Defender for Servers Plan 1 and Plan 2 provide different protection depth.
- Multicloud protection depends on healthy connectors and correct permissions.
- Coverage validation must include resources, components and telemetry.
- New subscriptions can create silent protection gaps.
Learning objectives
After completing this lesson, you should be able to explain how Microsoft Defender plans are selected, enabled, scoped and validated.
- Explain why Defender plans exist.
- Identify the main workload protection plans.
- Understand subscription and resource scope.
- Compare Defender for Servers Plan 1 and Plan 2.
- Recognise multicloud onboarding requirements.
- Validate workload protection coverage.
- Review licensing, cost and governance considerations.
What is a Defender plan?
A Microsoft Defender plan is a workload-specific security offering enabled through Defender for Cloud.
Each plan adds protection designed for a particular resource type, attack surface and telemetry source.
Why plans are separate
A virtual machine, storage account, Kubernetes cluster and database expose different risks and security signals.
Separate plans allow protection to be matched to the workload instead of applying one generic control to every resource.
Defender for Cloud is the platform
Defender for Cloud is the central posture and workload security platform.
Defender plans are the workload protection services enabled within that platform.
Main Defender plans
- Defender for Servers
- Defender for Storage
- Defender for Databases
- Defender for Containers
- Defender for Key Vault
- Defender for APIs
- Defender for App Service
- Defender for Resource Manager
- Defender for DNS
Plan availability changes
Plan names, supported resources and included features can change as Microsoft develops Defender for Cloud.
Production designs should always be checked against current documentation and the actual portal configuration.
Start with inventory
Plan selection begins with an accurate inventory of workloads, subscriptions, business owners and criticality.
You cannot design protection for resources you have not discovered or classified.
Start with risk
Internet exposure, sensitive data, identity privileges, regulatory obligations and business impact should influence plan selection.
Subscription scope
In Azure, Defender plans are commonly enabled at subscription scope.
New supported resources created within that subscription can then inherit the selected protection configuration.
Management-group strategy
Large organisations often use management groups and policy assignments to standardise Defender plan deployment across subscriptions.
Resource-level exceptions
Some plans or features allow resource-level configuration, exclusions or fine-grained settings.
Exceptions should be documented because they can create hidden coverage gaps.
Inheritance is not proof
A subscription-level setting may indicate that a plan is enabled, but individual resources can still lack required extensions, permissions or connectivity.
Auto-provisioning
Auto-provisioning can deploy required monitoring components to eligible resources.
Security teams must review deployment failures, unsupported systems and resources created before policies were applied.
Extensions and agents
Some capabilities depend on extensions, agents or service integrations. Others use agentless methods or cloud-native telemetry.
Agentless capabilities
Agentless assessment can provide visibility without installing a traditional agent inside every workload.
It does not automatically replace every runtime or response capability delivered by deeper integrations.
Permissions matter
Missing permissions can create partial onboarding that looks complete from a high-level dashboard.
Defender for Servers
Defender for Servers protects Windows and Linux machines across supported Azure, hybrid and multicloud environments.
Servers Plan 1
Plan 1 is designed to provide foundational server protection and Microsoft Defender for Endpoint integration for supported machines.
Servers Plan 2
Plan 2 provides broader server protection and can include additional vulnerability, monitoring and advanced workload capabilities.
Defender for Storage
Storage protection can add suspicious-access detection and malware scanning for supported storage activity.
Storage feature choices
Feature choices should reflect upload volume, data sensitivity, downstream processing risk and consumption-based cost.
Defender for Databases
Database protection is aligned to supported database technologies rather than one universal database plan.
Database scope
Azure-native databases, database servers and multicloud database services can require different onboarding methods.
Defender for Containers
Container protection spans supported Kubernetes environments, registries and runtime workloads.
Container dependencies
Container protection may depend on cloud connectors, cluster extensions, sensors and supported orchestration platforms.
Defender for APIs
API protection must be intentionally configured for supported APIs and management platforms.
Smaller plans still matter
Key Vault, Resource Manager, DNS and App Service protection can reveal attack activity invisible to server-focused tools.
AWS coverage
AWS environments can be connected using supported cloud connectors and permissions.
Google Cloud coverage
Google Cloud projects and organisations can be connected through supported onboarding workflows.
Azure Arc
Azure Arc can onboard supported non-Azure servers so they can receive Azure management and Defender for Servers capabilities.
Multicloud is not one checkbox
Connecting an external cloud account does not automatically enable every protection feature.
Free and paid capabilities
Defender for Cloud includes foundational posture capabilities, while Defender plans add paid workload protection and advanced features.
Pricing units vary
Different plans can use different billing measurements such as protected resources, servers, transactions or data volume.
Cost is part of design
Use criticality and exposure to determine where advanced protection provides the greatest value.
Trial periods
Trials must be tracked so protection does not unexpectedly change or create unplanned charges.
Plan enablement checklist
- Correct subscriptions or cloud accounts selected
- Relevant plans enabled
- Required permissions granted
- Auto-provisioning configured
- Extensions or agents deployed
- Plan-specific features reviewed
- Billing owner informed
- Coverage validation scheduled
Coverage validation
Coverage validation confirms that eligible workloads are actually protected, not merely that a plan toggle is enabled.
Validate protected resources
Review which resources appear as protected, unprotected, unsupported or unhealthy.
Validate telemetry
Confirm that expected security data is arriving from representative workloads.
Validate with testing
Where safe and approved, use controlled validation methods to confirm that alerts, recommendations and integrations work as designed.
Monitor configuration drift
Plans can be disabled, scopes can change and new subscriptions can be created outside the standard deployment process.
Ownership
Plan governance should define technical owner, billing owner and service owner.
What Agent Foskett checked
- Subscription creation date
- Defender plan status
- Management-group placement
- Policy assignment and compliance
- Endpoint onboarding state
- Extension and connector health
- Billing and ownership records
- Other subscriptions with the same gap
Operational lesson
Security coverage must be measured from the workload upward, not from the portal toggle downward.
Common mistakes
- Assuming Defender for Cloud automatically protects every resource.
- Enabling plans without reviewing cost.
- Ignoring newly created subscriptions.
- Failing to validate extensions and agents.
- Leaving multicloud connectors with incomplete permissions.
- Reporting configuration instead of actual coverage.
Best practices
- Maintain a complete workload inventory.
- Use policy to standardise plan deployment.
- Match plan depth to business risk.
- Validate coverage after enablement.
- Track cost, trials and feature changes.
- Document exclusions with owners and expiry dates.
Related Agent Foskett resources
Continue learning
What are Microsoft Defender plans?
Microsoft Defender plans add workload-specific protection to Microsoft Defender for Cloud for servers, storage, databases, containers, APIs, Key Vault and other supported resources.
Microsoft Defender Plans Overview Lesson
This Agent Foskett lesson explains plan enablement, subscription scope, Defender for Servers Plan 1 and Plan 2, multicloud connectors, licensing, cost governance, auto-provisioning and workload coverage validation.
