What is Microsoft Defender for Servers?
Microsoft Defender for Servers is a subscription that helps discover and assess the security posture of servers in Azure, Amazon Web Services, Google Cloud, and on-premises environments. It scans supported Windows and Linux servers for vulnerabilities such as missing patches, misconfigurations, or insecure software versions.
Companies can then use the Vulnerability Management dashboard in the Microsoft Defender portal to view vulnerability assessment results, filter and sort them by criteria such as server group, operating system, or exposure level, and drill down into the details of each vulnerability.
The dashboard can also prioritize vulnerabilities based on factors such as severity, exploitability, active threats, and the organization’s exposure. It then shows recommended actions to remediate them. IT teams can apply patches manually or use Azure Update Manager and other supported tools to manage the patch deployment process.
By using Defender for Servers, organizations can gain visibility into the security state of their servers, reduce the attack surface, and improve their compliance posture.
What are the differences between Plan 1 and Plan 2?
Defender for Servers is available in two plans: Plan 1 and Plan 2. Both plans support Windows and Linux servers across cloud and on-premises environments. Both also provide Microsoft Defender for Endpoint integration, endpoint detection and response, software inventory, and agent-based vulnerability assessment.
Plan 2 includes all the capabilities of Plan 1, along with additional features that make it more powerful and flexible.
Here are some of the key differences between Plan 1 and Plan 2:
- Plan 1 is the entry-level option and focuses on the endpoint detection and response capabilities provided through Microsoft Defender for Endpoint. Plan 2 includes the same protection along with additional vulnerability management and security posture features.
- Plan 2 provides agentless machine scanning for supported Azure virtual machines, AWS EC2 instances, and Google Cloud virtual machines. This allows Microsoft to assess software inventory and vulnerabilities and scan for malware and exposed secrets without installing another scanning agent on the machine.
- Plan 2 includes premium Microsoft Defender Vulnerability Management capabilities. These include security baseline assessments, vulnerable application blocking, browser extension assessment, digital certificate assessment, network share analysis, and hardware and firmware assessment.
- Plan 2 includes additional Defender for Cloud features such as operating system update assessment, security configuration assessment, file integrity monitoring, just-in-time virtual machine access, and network mapping. Some capabilities require Azure Arc onboarding or additional configuration.
- Both plans can protect servers outside Azure, but onboarding matters. Microsoft recommends connecting non-Azure and on-premises machines through Azure Arc to take full advantage of Defender for Servers features. Servers onboarded directly through Microsoft Defender for Endpoint may receive a more limited set of Plan 2 capabilities.
- Defender for Servers no longer relies on the legacy Log Analytics agent for most plan features. Microsoft Defender for Endpoint integration and agentless machine scanning now provide most of that functionality. A Log Analytics workspace is still needed for certain Plan 2 features, including file integrity monitoring and the included data-ingestion benefit.
Why should organizations upgrade to Plan 2?
Plan 2 offers significant advantages over Plan 1 for organizations that need more complete vulnerability management and security posture visibility. By upgrading to Plan 2, organizations can:
- Use agentless scanning to assess vulnerabilities, malware, and exposed secrets on supported Azure, AWS, and Google Cloud virtual machines.
- Gain access to premium Microsoft Defender Vulnerability Management capabilities and a more complete view of server risk.
- Use additional Microsoft Defender for Cloud features such as security baseline assessments, operating system update assessment, just-in-time access, file integrity monitoring, and other tools for reducing the attack surface.
For organizations that want to get the most out of Microsoft Defender Vulnerability Management and Defender for Cloud, we recommend upgrading to Plan 2 as soon as possible.
How can we help?
We specialize in helping customers secure and optimize their server environments. We have extensive experience deploying and managing Microsoft Defender for Endpoint and Microsoft Defender for Cloud. We can help organizations compare the two plans, confirm onboarding requirements, implement Plan 2, and take full advantage of Microsoft’s vulnerability management capabilities.
If you are interested in learning more about how we can help, please contact us today. We will be happy to provide you with a free consultation and a quote for our services.