Agent Foskett Academy • Microsoft Defender for Cloud • Module 1 • Lesson 4

Lesson 4 — Microsoft Defender Plans Overview

Microsoft Defender plans add workload-specific security capabilities to Microsoft Defender for Cloud. They determine which resources receive runtime threat protection, vulnerability assessment, malware scanning, endpoint integration and other advanced capabilities.

Defender for Cloud can be visible in a tenant without every workload being protected. Coverage depends on which plans are enabled, where they are enabled, which resources are supported and whether the required components are correctly deployed.

This lesson explains plan scope, subscription coverage, multicloud onboarding, Defender for Servers Plan 1 and Plan 2, feature validation, cost governance and the operational checks needed to prove that protection actually exists.

Seeing Defender for Cloud in the portal does not prove that every Defender plan is enabled.
Agent Foskett Microsoft Defender plans overview lesson
What you will learn

This lesson shows how Defender plans translate cloud security requirements into measurable workload coverage.

Plan purpose and scope
Servers Plan 1 and Plan 2
Coverage validation
Cost and governance

The Defender plan model

Cloud environment connected ↓ Workloads discovered ↓ Protection requirements identified ↓ Relevant Defender plans enabled ↓ Required components deployed ↓ Telemetry and assessments collected ↓ Recommendations, alerts and investigations ↓ Coverage continuously validated

Platform versus plan

AreaDefender for Cloud platformDefender plan
PurposeCentral posture and workload security managementProtection for a specific workload category
ExampleRecommendations, inventory and alertsDefender for Servers or Defender for Storage
ScopeConnected cloud environmentSelected subscriptions, accounts, projects or resources
CostFoundational capabilities may be available without paid workload plansPaid according to plan and protected usage

Defender for Servers Plan 1 and Plan 2

AreaPlan 1Plan 2
Primary useFoundational endpoint-focused server protectionBroader advanced server protection
Endpoint integrationSupportedSupported
Advanced capabilitiesMore limitedExpanded
Typical scopeLower-risk or cost-sensitive server estatesCritical, regulated or higher-risk server estates
Always confirm current Plan 1 and Plan 2 inclusions before making a licensing decision.

Plan scope workflow

Tenant and management groups ↓ Subscriptions selected ↓ Defender plans enabled ↓ Policy assignments and auto-provisioning ↓ Resources inherit configuration ↓ Required agents, extensions or connectors deploy ↓ Coverage and telemetry validated

Cost governance model

Workload inventory + Business criticality + Threat exposure + Regulatory requirements + Plan capabilities + Consumption and pricing model ↓ Protection decision ↓ Budget owner and approval ↓ Ongoing cost and coverage review

Agent Foskett investigation: “The protection was never enabled…”

A production virtual machine was compromised ↓ The SOC opened Defender for Cloud ↓ No server alert existed ↓ The first assumption: “Defender missed the attack.” ↓ Agent Foskett checked the subscription ↓ Defender for Servers was not enabled ↓ The machine had: • No expected Defender for Endpoint onboarding • No validated vulnerability assessment • No server workload detections • No documented exception ↓ The subscription had been created outside the standard process ↓ The server looked managed ↓ But workload protection had never been configured ↓ The subscription was brought under policy ↓ Coverage reporting was added for all future subscriptions
Defender did not fail to alert. The Defender plan had never been enabled.

Key takeaways

  • Defender plans provide workload-specific protection within Defender for Cloud.
  • The platform and paid Defender plans are not the same thing.
  • Plan selection should follow workload inventory, risk and criticality.
  • Subscription-level enablement does not guarantee resource-level coverage.
  • Policy and auto-provisioning help reduce configuration drift.
  • Defender for Servers Plan 1 and Plan 2 provide different protection depth.
  • Multicloud protection depends on healthy connectors and correct permissions.
  • Coverage validation must include resources, components and telemetry.
  • New subscriptions can create silent protection gaps.

Learning objectives

After completing this lesson, you should be able to explain how Microsoft Defender plans are selected, enabled, scoped and validated.

  • Explain why Defender plans exist.
  • Identify the main workload protection plans.
  • Understand subscription and resource scope.
  • Compare Defender for Servers Plan 1 and Plan 2.
  • Recognise multicloud onboarding requirements.
  • Validate workload protection coverage.
  • Review licensing, cost and governance considerations.

What is a Defender plan?

A Microsoft Defender plan is a workload-specific security offering enabled through Defender for Cloud.

Each plan adds protection designed for a particular resource type, attack surface and telemetry source.

Why plans are separate

A virtual machine, storage account, Kubernetes cluster and database expose different risks and security signals.

Separate plans allow protection to be matched to the workload instead of applying one generic control to every resource.

Defender for Cloud is the platform

Defender for Cloud is the central posture and workload security platform.

Defender plans are the workload protection services enabled within that platform.

Main Defender plans

  • Defender for Servers
  • Defender for Storage
  • Defender for Databases
  • Defender for Containers
  • Defender for Key Vault
  • Defender for APIs
  • Defender for App Service
  • Defender for Resource Manager
  • Defender for DNS

Plan availability changes

Plan names, supported resources and included features can change as Microsoft develops Defender for Cloud.

Production designs should always be checked against current documentation and the actual portal configuration.

Start with inventory

Plan selection begins with an accurate inventory of workloads, subscriptions, business owners and criticality.

You cannot design protection for resources you have not discovered or classified.

Start with risk

Internet exposure, sensitive data, identity privileges, regulatory obligations and business impact should influence plan selection.

Subscription scope

In Azure, Defender plans are commonly enabled at subscription scope.

New supported resources created within that subscription can then inherit the selected protection configuration.

Management-group strategy

Large organisations often use management groups and policy assignments to standardise Defender plan deployment across subscriptions.

Resource-level exceptions

Some plans or features allow resource-level configuration, exclusions or fine-grained settings.

Exceptions should be documented because they can create hidden coverage gaps.

Inheritance is not proof

A subscription-level setting may indicate that a plan is enabled, but individual resources can still lack required extensions, permissions or connectivity.

Auto-provisioning

Auto-provisioning can deploy required monitoring components to eligible resources.

Security teams must review deployment failures, unsupported systems and resources created before policies were applied.

Extensions and agents

Some capabilities depend on extensions, agents or service integrations. Others use agentless methods or cloud-native telemetry.

Agentless capabilities

Agentless assessment can provide visibility without installing a traditional agent inside every workload.

It does not automatically replace every runtime or response capability delivered by deeper integrations.

Permissions matter

Missing permissions can create partial onboarding that looks complete from a high-level dashboard.

Defender for Servers

Defender for Servers protects Windows and Linux machines across supported Azure, hybrid and multicloud environments.

Servers Plan 1

Plan 1 is designed to provide foundational server protection and Microsoft Defender for Endpoint integration for supported machines.

Servers Plan 2

Plan 2 provides broader server protection and can include additional vulnerability, monitoring and advanced workload capabilities.

Defender for Storage

Storage protection can add suspicious-access detection and malware scanning for supported storage activity.

Storage feature choices

Feature choices should reflect upload volume, data sensitivity, downstream processing risk and consumption-based cost.

Defender for Databases

Database protection is aligned to supported database technologies rather than one universal database plan.

Database scope

Azure-native databases, database servers and multicloud database services can require different onboarding methods.

Defender for Containers

Container protection spans supported Kubernetes environments, registries and runtime workloads.

Container dependencies

Container protection may depend on cloud connectors, cluster extensions, sensors and supported orchestration platforms.

Defender for APIs

API protection must be intentionally configured for supported APIs and management platforms.

Smaller plans still matter

Key Vault, Resource Manager, DNS and App Service protection can reveal attack activity invisible to server-focused tools.

AWS coverage

AWS environments can be connected using supported cloud connectors and permissions.

Google Cloud coverage

Google Cloud projects and organisations can be connected through supported onboarding workflows.

Azure Arc

Azure Arc can onboard supported non-Azure servers so they can receive Azure management and Defender for Servers capabilities.

Multicloud is not one checkbox

Connecting an external cloud account does not automatically enable every protection feature.

Free and paid capabilities

Defender for Cloud includes foundational posture capabilities, while Defender plans add paid workload protection and advanced features.

Pricing units vary

Different plans can use different billing measurements such as protected resources, servers, transactions or data volume.

Cost is part of design

Use criticality and exposure to determine where advanced protection provides the greatest value.

Trial periods

Trials must be tracked so protection does not unexpectedly change or create unplanned charges.

Plan enablement checklist

  • Correct subscriptions or cloud accounts selected
  • Relevant plans enabled
  • Required permissions granted
  • Auto-provisioning configured
  • Extensions or agents deployed
  • Plan-specific features reviewed
  • Billing owner informed
  • Coverage validation scheduled

Coverage validation

Coverage validation confirms that eligible workloads are actually protected, not merely that a plan toggle is enabled.

Validate protected resources

Review which resources appear as protected, unprotected, unsupported or unhealthy.

Validate telemetry

Confirm that expected security data is arriving from representative workloads.

Validate with testing

Where safe and approved, use controlled validation methods to confirm that alerts, recommendations and integrations work as designed.

Monitor configuration drift

Plans can be disabled, scopes can change and new subscriptions can be created outside the standard deployment process.

Ownership

Plan governance should define technical owner, billing owner and service owner.

What Agent Foskett checked

  • Subscription creation date
  • Defender plan status
  • Management-group placement
  • Policy assignment and compliance
  • Endpoint onboarding state
  • Extension and connector health
  • Billing and ownership records
  • Other subscriptions with the same gap

Operational lesson

Security coverage must be measured from the workload upward, not from the portal toggle downward.

Common mistakes

  • Assuming Defender for Cloud automatically protects every resource.
  • Enabling plans without reviewing cost.
  • Ignoring newly created subscriptions.
  • Failing to validate extensions and agents.
  • Leaving multicloud connectors with incomplete permissions.
  • Reporting configuration instead of actual coverage.

Best practices

  • Maintain a complete workload inventory.
  • Use policy to standardise plan deployment.
  • Match plan depth to business risk.
  • Validate coverage after enablement.
  • Track cost, trials and feature changes.
  • Document exclusions with owners and expiry dates.

Related Agent Foskett resources

Continue building Microsoft Defender for Cloud posture, workload protection and plan-management skills.

Continue learning

Continue Module 1 with a detailed look at Microsoft Defender for Servers and the protection it provides to Windows and Linux machines.

What are Microsoft Defender plans?

Microsoft Defender plans add workload-specific protection to Microsoft Defender for Cloud for servers, storage, databases, containers, APIs, Key Vault and other supported resources.

Microsoft Defender Plans Overview Lesson

This Agent Foskett lesson explains plan enablement, subscription scope, Defender for Servers Plan 1 and Plan 2, multicloud connectors, licensing, cost governance, auto-provisioning and workload coverage validation.