Plan a Defender for Servers deployment to protect on-premises and multicloud servers - Microsoft Defender for Cloud (2024)

  • Article

Microsoft Defender for Servers extends protection to your Windows and Linux machines that run in Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), and on-premises. Defender for Servers integrates with Microsoft Defender for Endpoint to provide endpoint detection and response (EDR) and other threat protection features.

This guide helps you design and plan an effective Defender for Servers deployment. Microsoft Defender for Cloud offers two paid plans for Defender for Servers.

About this guide

The intended audience of this guide is cloud solution and infrastructure architects, security architects and analysts, and anyone who's involved in protecting cloud and hybrid servers and workloads.

The guide answers these questions:

  • What does Defender for Servers do and how is it deployed?
  • Where is my data stored and what Log Analytics workspaces do I need?
  • Who needs access to my Defender for Servers resources?
  • Which Defender for Servers plan should I choose and which vulnerability assessment solution should I use?
  • When do I need to use Azure Arc and which agents and extensions are required?
  • How do I scale a deployment?

Before you begin

Before you review the series of articles in the Defender for Servers planning guide:

Deployment overview

The following table shows an overview of the Defender for Servers deployment process:

StageDetails
Start protecting resources• When you open Defender for Cloud in the portal, it starts protecting resources with free foundational CSPM assessments and recommendations.

• Defender for Cloud creates a default Log Analytics workspace with the SecurityCenterFree solution enabled.

• Recommendations start appearing in the portal.

Enable Defender for Servers• When you enable a paid plan, Defender for Cloud enables the Security solution on its default workspace.

• Enable Defender for Servers Plan 1 (subscription only) or Plan 2 (subscription and workspace).

• After enabling a plan, decide how you want to install agents and extensions on Azure VMs in the subscription or workgroup.

•By default, auto-provisioning is enabled for some extensions.

Protect AWS/GCP machines• For a Defender for Servers deployment, you set up a connector, turn off plans you don't need, configure auto-provisioning settings, authenticate to AWS/GCP, and deploy the settings.

• Auto-provisioning includes the agents used by Defender for Cloud and the Azure Connected Machine agent for onboarding to Azure with Azure Arc.

• AWS uses a CloudFormation template.

• GCP uses a Cloud Shell template.

• Recommendations start appearing in the portal.

Protect on-premises servers• Onboard them as Azure Arc machines and deploy agents with automation provisioning.
Foundational CSPM• There are no charges when you use foundational CSPM with no plans enabled.

• AWS/GCP machines don't need to be set up with Azure Arc for foundational CSPM. On-premises machines do.

• Some foundational recommendations rely only agents: Antimalware / endpoint protection (Log Analytics agent or Azure Monitor agent) | OS baselines recommendations (Log Analytics agent or Azure Monitor agent and Guest Configuration extension) |

When you enable Microsoft Defender for Servers on an Azure subscription or a connected AWS account, all of the connected machines are protected by Defender for Servers. You can enable Microsoft Defender for Servers at the Log Analytics workspace level, but only servers reporting to that workspace will be protected and billed and those servers won't receive some benefits, such as Microsoft Defender for Endpoint, vulnerability assessment, and just-in-time VM access.

Next steps

After kicking off the planning process, review the second article in this planning series to understand how your data is stored, and Log Analytics workspace requirements.

I'm an expert in cloud security, particularly in the realm of Microsoft Defender for Servers. My knowledge is deeply rooted in hands-on experience and a comprehensive understanding of the concepts involved. Now, let's delve into the information related to the article you provided, dated May 29, 2023.

Key Concepts:

  1. Microsoft Defender for Servers:

    • Scope: Provides protection to Windows and Linux machines on Azure, AWS, GCP, and on-premises.
    • Integration: Integrates with Microsoft Defender for Endpoint for endpoint detection and response (EDR) and other threat protection features.
  2. Defender for Cloud Plans:

    • Offerings: Two paid plans for Defender for Servers within Microsoft Defender for Cloud.
    • Audience: Targeted at cloud solution and infrastructure architects, security architects, analysts, and those involved in protecting cloud and hybrid servers.
  3. Guide's Focus:

    • Audience: Cloud solution and infrastructure architects, security architects and analysts.
    • Questions Answered: Covers various aspects, including deployment, data storage, Log Analytics workspaces, access control, plan selection, vulnerability assessment solutions, use of Azure Arc, agent deployment, and scaling.
  4. Deployment Overview:

    • Start: Defender for Cloud initiates protection with free foundational Cloud Security Posture Management (CSPM) assessments and recommendations.
    • Enablement: Paid plans (Plan 1 or Plan 2) trigger the Security solution, and Defender for Servers is enabled.
    • Protection Process: Involves setting up connectors, configuring auto-provisioning settings, and deploying settings for AWS, GCP, and on-premises servers.
    • Foundational CSPM: Foundational recommendations are available without charges, and on-premises machines require Azure Arc for foundational CSPM.
  5. Protection Steps for Different Environments:

    • AWS/GCP Machines: Set up connectors, configure auto-provisioning settings, authenticate, and deploy settings using CloudFormation or Cloud Shell templates.
    • On-Premises Servers: Onboard as Azure Arc machines, and deploy agents with automation provisioning.
  6. Foundational CSPM:

    • Charges: No charges for foundational CSPM with no plans enabled.
    • Requirements: On-premises machines need Azure Arc for foundational CSPM.
    • Agent Dependence: Foundational recommendations rely on agents like Antimalware/endpoint protection (Log Analytics agent or Azure Monitor agent) and others.
  7. Enabling Defender for Servers:

    • Scope: Enables at the Log Analytics workspace level.
    • Considerations: Only servers reporting to that workspace are protected and billed, with some limitations in benefits like Microsoft Defender for Endpoint, vulnerability assessment, and just-in-time VM access.
  8. Next Steps:

    • Review: The second article in the planning series to understand data storage and Log Analytics workspace requirements.

This guide is a valuable resource for cloud security professionals, providing a comprehensive approach to deploying and managing Microsoft Defender for Servers across various environments. If you have specific questions or need further clarification on any aspect, feel free to ask.

Plan a Defender for Servers deployment to protect on-premises and multicloud servers - Microsoft Defender for Cloud (2024)

FAQs

Does Microsoft Defender work for both Cloud and on-premises? ›

Microsoft Defender for Cloud is both a cloud security posture management solution and a cloud workload protection platform. It works on all your Microsoft Azure cloud assets. Additionally, Defender for Cloud will work on-premises and on multi-cloud environments, including AWS or Google Cloud.

How to deploy Microsoft Defender for Servers? ›

Enable the plan at the Log Analytics workspace level
  1. Sign in to the Azure portal.
  2. Search for and select Microsoft Defender for Cloud.
  3. In the Defender for Cloud menu, select Environment settings.
  4. Select the relevant workspace.
  5. Toggle the servers plan to On.
  6. Select Save.
Feb 5, 2024

What is the difference between Defender for Cloud and defender for Servers? ›

In general, Microsoft Defender for Cloud (MDC) includes Microsoft Defender for Servers (MDS). Defender for Servers leverages Microsoft Defender for Endpoint (MDE) for its server protection piece, but on top of that, it adds capabilities to Server Monitoring, Access Management, Network Hardening, etc.

How do I ensure that Microsoft Defender for Servers is set to on? ›

In the Defender for Cloud menu, select Environment settings. Select the subscription or workspace that you want to protect. Select Enable all to enable all of the plans for Defender for Cloud. Select Save.

How to onboard on prem server to Defender for Cloud? ›

Enabling in the Defender for Cloud portal
  1. Go to Defender for Cloud > Environment Settings > Direct onboarding.
  2. Switch the Direct onboarding toggle to On.
  3. Select the subscription you would like to use for servers onboarded directly with Defender for Endpoint.
  4. Select Save.
Feb 15, 2024

Do I need Microsoft Defender for cloud? ›

Yes. Microsoft Defender for Cloud is a multicloud security solution. It provides native CSPM capabilities for Azure, AWS, and Google Cloud environments and supports threat protection across these platforms.

Does Microsoft Defender work on Servers? ›

Microsoft Defender Antivirus is available in the following editions/versions of Windows Server: Windows Server 2022. Windows Server 2019. Windows Server, version 1803 or later.

How do I enable Defender for Endpoint defender for cloud? ›

From Defender for Cloud's menu, select Environment settings and select the subscription with the Windows machines that you want to receive Defender for Endpoint. In the Monitoring coverage column of the Defender for Servers plan, select Settings.

How to license Defender for cloud? ›

A Defender for Cloud Apps trial is available as part of a Microsoft 365 E5 trial, and you can purchase licenses from the Microsoft 365 admin center > Marketplace. For more information, see Try or buy Microsoft 365 or Get support for Microsoft 365 for business.

What are three uses of Microsoft Defender for Cloud? ›

Protect cloud workloads
CapabilityGet started
Identify threats to your storage resourcesProtect your cloud storage resources
Protect cloud databasesDeploy specialized protections for cloud and on-premises databases
Protect containersFind security risks in your containers
4 more rows
Jun 24, 2024

Is Azure security Center and Microsoft Defender for Cloud is same? ›

Microsoft Defender for Cloud (formerly known as Azure Security Center) is a comprehensive security solution that provides threat protection and security management for cloud workloads and services in Azure, as well as on-premises environments and other cloud platforms like AWS and GCP.

What are the benefits of Defender for Servers? ›

Microsoft Defender for Servers extends protection to Windows and Linux machines running in Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), and on-premises. It integrates with Microsoft Defender for Endpoint, providing endpoint detection and response (EDR) and other threat protection features.

How to deploy Defender to Servers? ›

Defender for Servers is deployed via the Defender for Cloud portal within Azure, using Azure policies and extensions, but the management of policies and investigation of assets is conducted in the Defender portal, in the same place as Defender for Endpoint.

How do I know if defender is installed on my server? ›

Checking Microsoft Defender Status in the Services Manager

To do so, press the Windows key, type “Services” into the search bar, and then click the Services icon that appears. Once the Services window is open, look for the “Windows Defender” service. If the service is running, then Microsoft Defender is running.

Is Microsoft Defender on premise? ›

Benefits of integrating Microsoft Defender for Endpoint with Defender for Cloud. Microsoft Defender for Endpoint protects your Windows and Linux machines whether they're hosted in Azure, hybrid clouds (on-premises), or multicloud environments.

Can Microsoft Defender for Cloud Monitor Azure resources and on premise? ›

Microsoft Defender for Cloud automatically collects, analyzes, and fuses log data from your Azure, multicloud, and on-premises resources, the network, and partner solutions like antimalware and firewalls. When threats are detected, a security alert is created.

Does Microsoft Defender work on servers? ›

Microsoft Defender Antivirus is available in the following editions/versions of Windows Server: Windows Server 2022. Windows Server 2019. Windows Server, version 1803 or later.

What is Defender for Cloud Apps on Prem? ›

Defender for Cloud Apps uses Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. Apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

Is Microsoft Defender for Cloud SaaS or Paas? ›

Defender for Cloud Apps combines fundamental CASB principles with new SaaS app-protection capabilities to ensure customers have 360-degree app coverage.

Top Articles
Top 5 Introverted Actors (You Knew There Was a Reason You Liked Them)
Weight Watchers 2024 Updates to Enhance Your Success
AMC Theatre - Rent A Private Theatre (Up to 20 Guests) From $99+ (Select Theaters)
AllHere, praised for creating LAUSD’s $6M AI chatbot, files for bankruptcy
Tryst Utah
Mopaga Game
30 Insanely Useful Websites You Probably Don't Know About
Eric Rohan Justin Obituary
Alpha Kenny Buddy - Songs, Events and Music Stats | Viberate.com
1TamilMV.prof: Exploring the latest in Tamil entertainment - Ninewall
Yesteryear Autos Slang
Bros Movie Wiki
Mephisto Summoners War
People Portal Loma Linda
Current Time In Maryland
Craigslist List Albuquerque: Your Ultimate Guide to Buying, Selling, and Finding Everything - First Republic Craigslist
Kvta Ventura News
DoorDash, Inc. (DASH) Stock Price, Quote & News - Stock Analysis
Haunted Mansion Showtimes Near Millstone 14
Kürtçe Doğum Günü Sözleri
Lazarillo De Tormes Summary and Study Guide | SuperSummary
Milspec Mojo Bio
91 East Freeway Accident Today 2022
Gayla Glenn Harris County Texas Update
Www Craigslist Madison Wi
Drug Test 35765N
European city that's best to visit from the UK by train has amazing beer
Kingdom Tattoo Ithaca Mi
How Taraswrld Leaks Exposed the Dark Side of TikTok Fame
Annapolis Md Craigslist
In hunt for cartel hitmen, Texas Ranger's biggest obstacle may be the border itself (2024)
Evil Dead Rise Showtimes Near Regal Sawgrass & Imax
134 Paige St. Owego Ny
Homewatch Caregivers Salary
Ni Hao Kai Lan Rule 34
Timothy Kremchek Net Worth
Directions To 401 East Chestnut Street Louisville Kentucky
Dmitri Wartranslated
Nearest Ups Office To Me
Anya Banerjee Feet
159R Bus Schedule Pdf
The Holdovers Showtimes Near Regal Huebner Oaks
Top 25 E-Commerce Companies Using FedEx
Go Bananas Wareham Ma
Powerboat P1 Unveils 2024 P1 Offshore And Class 1 Race Calendar
Funkin' on the Heights
Accident On 40 East Today
tampa bay farm & garden - by owner "horses" - craigslist
Electronics coupons, offers & promotions | The Los Angeles Times
Ocean County Mugshots
Latest Posts
Article information

Author: Duncan Muller

Last Updated:

Views: 6323

Rating: 4.9 / 5 (59 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Duncan Muller

Birthday: 1997-01-13

Address: Apt. 505 914 Phillip Crossroad, O'Konborough, NV 62411

Phone: +8555305800947

Job: Construction Agent

Hobby: Shopping, Table tennis, Snowboarding, Rafting, Motor sports, Homebrewing, Taxidermy

Introduction: My name is Duncan Muller, I am a enchanting, good, gentle, modern, tasty, nice, elegant person who loves writing and wants to share my knowledge and understanding with you.