defender-for-servers
Microsoft Defender for Servers
Defender for Servers is the server-focused plan inside Microsoft Defender for Cloud. It extends Microsoft Defender for Endpoint (MDE) to Azure VMs, Azure Arc-enabled machines (on-prem, AWS EC2, GCP Compute), and VM Scale Sets, and adds server-specific controls: just-in-time VM access, file integrity monitoring, agentless disk scanning, and vulnerability assessment.
When to use
Designing or hardening protection for server workloads — IaaS VMs, hybrid/multicloud servers via Arc, jump hosts, domain controllers, line-of-business servers. Use this skill for plan selection, MDE-for-Servers onboarding, FIM, JIT, and agentless vs agent-based scanning trade-offs.
Do not use this skill for client endpoints (defender-for-endpoint), AKS/container hosts
(defender-for-containers), Azure storage accounts (defender-for-storage), or generic
Defender for Cloud posture (defender-for-cloud-hardening).