Tag: Defender for Servers

Configure Defender for Servers settings, including vulnerability scanning, and endpoint detection and response (EDR) (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for servers and virtual machines (VMs)
      --> Configure Defender for Servers settings, including vulnerability scanning, and endpoint detection and response (EDR)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

This topic focuses on configuring Microsoft Defender for Servers in Microsoft Defender for Cloud, including:

  • Selecting Defender for Servers Plan 1 or Plan 2
  • Configuring vulnerability scanning
  • Understanding agent-based and agentless assessments
  • Integrating Microsoft Defender for Endpoint
  • Configuring endpoint detection and response (EDR)
  • Protecting Azure, on-premises, AWS, and GCP servers
  • Reviewing security recommendations and protection coverage
  • Troubleshooting incomplete or unhealthy protection

1. What Is Microsoft Defender for Servers?

Microsoft Defender for Servers is a workload protection plan in Microsoft Defender for Cloud that protects supported Windows and Linux servers and virtual machines.

It can provide:

  • Endpoint detection and response
  • Antivirus and antimalware protection
  • Vulnerability assessment
  • Software inventory
  • Security recommendations
  • Security configuration assessment
  • File Integrity Monitoring
  • Agentless secret scanning
  • Agentless malware scanning
  • Agentless software inventory
  • Operating-system update assessment
  • Regulatory compliance insights
  • Integration with Microsoft Defender for Endpoint
  • Integration with Microsoft Sentinel

Defender for Servers supports servers running in:

  • Azure
  • On-premises datacenters
  • Amazon Web Services
  • Google Cloud Platform
  • Other supported hybrid environments

For non-Azure servers, Azure Arc-enabled servers is generally the preferred onboarding method when the organization requires the broadest Defender for Servers functionality.

Defender for Servers is not a replacement for:

  • Operating-system hardening
  • Patch management
  • Identity security
  • Network segmentation
  • Secure application development
  • Backup protection
  • Firewall configuration
  • Incident response procedures

Instead, it provides centralized security visibility, assessment, detection, and protection capabilities across supported server environments.


2. Defender for Servers Plans

Defender for Servers has two primary paid plans:

  • Plan 1
  • Plan 2

Plan 1

Plan 1 is the entry-level plan and focuses primarily on endpoint protection capabilities provided through the Microsoft Defender for Endpoint integration.

Important capabilities include:

  • Endpoint detection and response
  • Microsoft Defender for Endpoint integration
  • Antivirus and antimalware protection
  • Threat detection
  • Endpoint investigation
  • Attack surface reduction capabilities
  • Vulnerability information through the Defender for Endpoint sensor

Plan 1 is appropriate when the primary requirement is server endpoint protection and EDR.

Plan 2

Plan 2 includes Plan 1 capabilities and adds advanced server security and assessment capabilities.

Depending on the supported server type and configuration, Plan 2 can provide:

  • Agentless vulnerability assessment
  • Agentless software inventory
  • Agentless secret scanning
  • Agentless malware scanning
  • File Integrity Monitoring
  • Operating-system configuration assessment
  • Security baseline assessment
  • Operating-system update assessment
  • Premium Microsoft Defender Vulnerability Management capabilities
  • Additional security posture capabilities
  • A free daily data-ingestion benefit for eligible data types and supported configurations

Plan 2 also supports advanced vulnerability-management capabilities such as certificate assessment, security baseline assessment, and vulnerable application blocking where supported.

Plan Comparison

CapabilityPlan 1Plan 2
Microsoft Defender for Endpoint integrationYesYes
EDRYesYes
Antivirus and antimalwareYesYes
Agent-based vulnerability assessmentYesYes
Agentless vulnerability assessmentNoYes
Agentless software inventoryLimited or not availableYes, where supported
Agentless secret scanningNoYes, where supported
Agentless malware scanningNoYes, where supported
File Integrity MonitoringNoYes
Advanced Defender Vulnerability Management capabilitiesNoYes
Operating-system security baseline assessmentNoYes, where supported
Operating-system update assessmentNoYes

Feature availability varies by:

  • Operating system
  • Azure or non-Azure environment
  • Azure Arc onboarding status
  • Subscription and resource scope
  • Defender for Servers plan
  • Agent availability
  • Current Microsoft support matrix

Do not assume that every feature is available for every Azure VM, Arc-enabled server, AWS instance, or GCP instance.


3. Where Defender for Servers Is Configured

Defender for Servers is configured in Microsoft Defender for Cloud.

A typical configuration path is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the relevant Azure subscription, AWS account, or GCP project.
  4. Open the Defender plans page.
  5. Locate Defender for Servers.
  6. Select the desired plan.
  7. Open the plan’s settings to configure monitoring and security features.

When Defender for Servers is enabled, several capabilities are enabled by default. You can then modify individual settings according to the organization’s requirements.

Common Configuration Areas

Defender for Servers settings can include:

  • Endpoint protection
  • Vulnerability assessment
  • Agentless scanning
  • File Integrity Monitoring
  • Security configuration assessment
  • Operating-system update assessment
  • Data collection
  • Log Analytics workspace configuration
  • Resource-level exclusions
  • Coverage and monitoring settings

4. Subscription-Level and Resource-Level Configuration

Microsoft generally recommends enabling Defender for Servers at the subscription level.

Subscription-level enablement provides:

  • Consistent coverage
  • Easier governance
  • Centralized configuration
  • Better visibility into protected and unprotected resources
  • Simplified licensing management
  • Easier policy-based deployment

However, resource-level configuration can be useful when:

  • Different machines require different plans.
  • A specific server must be excluded.
  • A phased deployment is required.
  • A test environment is being evaluated.
  • The organization needs more granular coverage.

Important Plan Scope Detail

Plan 1 can be enabled or disabled at the resource level.

Plan 2 is generally enabled at the subscription level. It can be disabled at the resource level, but it cannot be enabled at the resource level in the same way as Plan 1.

Exam Tip

If a question asks for the simplest way to protect all supported machines in a subscription, choose subscription-level Defender for Servers enablement unless the scenario specifically requires granular resource-level configuration.


5. Azure, Hybrid, and Multicloud Protection

Azure Virtual Machines

Azure VMs are already Azure resources. Defender for Cloud can associate them directly with the subscription and resource group.

The general process is:

  1. Enable Defender for Servers for the subscription.
  2. Select Plan 1 or Plan 2.
  3. Configure the required monitoring and scanning settings.
  4. Verify Defender for Endpoint and vulnerability-assessment status.

On-Premises Servers

On-premises servers should generally be onboarded as Azure Arc-enabled servers.

Azure Arc provides:

  • An Azure resource representation
  • An Azure resource ID
  • Resource-group placement
  • Azure RBAC integration
  • Azure Policy integration
  • Extension deployment
  • Defender for Cloud integration

AWS and GCP Servers

AWS accounts and GCP projects can be connected to Defender for Cloud through native multicloud connectors.

The connector can help discover and onboard supported machines as Azure Arc-enabled servers. This allows Defender for Cloud to apply supported server protection capabilities to those machines.

For the broadest Defender for Servers functionality, AWS and GCP machines generally require Azure Arc onboarding.


6. Azure Arc and Defender for Servers

Azure Arc is important because Defender for Servers is not simply a dashboard that reads cloud inventory.

The Azure Connected Machine agent can:

  • Establish the machine’s relationship with Azure
  • Provide the machine’s Azure resource identity
  • Enable supported extensions
  • Support policy and configuration assessment
  • Allow Defender for Cloud to deploy required components
  • Provide management and security connectivity

A typical architecture is:

Azure VM
|
+-----------------------------+
|
On-premises server |
| |
AWS EC2 instance |
| |
GCP Compute Engine instance |
| |
v v
Azure Arc-enabled server ---> Microsoft Defender for Cloud
|
+--> Defender for Servers
|
+--> Defender for Endpoint
|
+--> Defender Vulnerability Management
|
+--> Security recommendations
|
+--> Microsoft Sentinel

Directly installing the Defender for Endpoint agent on a non-Azure server can provide endpoint protection and EDR, but it is not equivalent to full Azure Arc onboarding. Some Defender for Servers capabilities require Arc-enabled onboarding.


7. Vulnerability Scanning

Vulnerability scanning identifies weaknesses in software and operating-system configurations.

Examples include:

  • Missing security updates
  • Vulnerable software versions
  • Known CVEs
  • Unsupported applications
  • Insecure configurations
  • Vulnerable browser extensions
  • Weak certificates
  • Exposed secrets
  • Applications that should be blocked or remediated

Defender for Servers integrates with Microsoft Defender Vulnerability Management.

Vulnerability information can be viewed through Defender for Cloud and the unified vulnerability-management experience in the Microsoft Defender portal.

Vulnerability Scanning Methods

Defender for Servers supports two main scanning approaches:

  1. Agent-based vulnerability scanning
  2. Agentless vulnerability scanning

8. Agent-Based Vulnerability Scanning

Agent-based scanning uses the Microsoft Defender for Endpoint sensor on the machine.

The sensor collects information about:

  • Installed software
  • Software versions
  • Operating-system information
  • Vulnerability exposure
  • Security configuration
  • Endpoint security state

Agent-based scanning is available with Defender for Servers Plan 1 and Plan 2 when the Defender for Endpoint integration is enabled and supported.

Advantages

  • Detailed machine-level information
  • Continuous assessment
  • Integration with endpoint protection
  • Fresh vulnerability data
  • Unified endpoint and vulnerability view
  • Works across supported Azure, Arc, AWS, and GCP machines

Requirements

Agent-based scanning generally requires:

  • A supported operating system
  • Defender for Servers Plan 1 or Plan 2
  • Defender for Endpoint integration
  • A healthy Defender for Endpoint sensor
  • Required network connectivity
  • Successful agent provisioning

For on-premises machines, Defender for Endpoint must generally be installed for agent-based vulnerability scanning.


9. Agentless Vulnerability Scanning

Agentless scanning evaluates supported machines without requiring a traditional scanning agent inside the operating system.

Agentless scanning is available with Defender for Servers Plan 2.

It can provide information about:

  • Software inventory
  • Vulnerabilities
  • Secrets
  • Malware
  • Machine posture
  • Other supported security assessments

Advantages

  • Minimal impact on machine performance
  • No additional operating-system scanning agent for supported capabilities
  • Useful when another EDR product is installed
  • Useful for broad cloud coverage
  • Can identify security issues even when agent-based coverage is incomplete

Limitations

Agentless scanning is not universally available for every:

  • Operating system
  • Cloud platform
  • Server type
  • Feature
  • Configuration
  • Security assessment

Always verify support before designing an architecture around agentless scanning.


10. How Agent-Based and Agentless Scanning Work Together

When both agent-based and agentless scanning are available, Defender for Cloud can present a unified view.

Typical behavior includes:

  • Machines with only agent-based scanning show agent-based results.
  • Machines with only agentless scanning show agentless results.
  • Machines with both methods generally use agent-based results for better freshness.
  • Machines using a partner vulnerability solution may show partner results by default.
  • Agentless results can be used for machines without a functioning partner scanner or when Defender Vulnerability Management results are explicitly selected.

This behavior prevents duplicate findings and helps Defender for Cloud select the most appropriate available source.


11. Partner Vulnerability Scanners

Organizations may already use a third-party vulnerability scanner.

Defender for Cloud supports partner-based vulnerability assessment solutions, including supported Qualys and Rapid7 integrations.

With a partner solution:

  1. The partner scanner evaluates the machine.
  2. Vulnerability results are reported to the partner management platform.
  3. The partner platform sends relevant findings to Defender for Cloud.
  4. Security teams can review the findings in Defender for Cloud.
  5. Administrators can open the partner console for detailed information.

A paid Defender for Servers plan is not necessarily required merely to use a supported partner vulnerability-assessment solution. However, other Defender for Cloud capabilities may require a paid plan.

Exam Tip

If the question asks for a Microsoft-native vulnerability solution, choose Microsoft Defender Vulnerability Management.

If the question describes an existing Qualys or Rapid7 deployment, consider the supported partner integration instead of automatically deploying another scanner.


12. Configuring Vulnerability Assessment

A typical configuration process is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the target subscription.
  4. Open Defender for Servers settings.
  5. Select Monitoring coverage or the relevant settings area.
  6. Locate Vulnerability assessment for machines.
  7. Select the required assessment solution.
  8. Apply the configuration.
  9. Verify that the scanner is deployed or active.
  10. Review the resulting recommendations and findings.

Vulnerability scanning is enabled by default in many Defender for Servers configurations, but administrators can manually modify the scanning settings when necessary.

Required Permissions

The permissions needed depend on the deployment method.

For example:

  • An administrator deploying the scanner may require Owner-level permissions at the resource-group level.
  • A security reader can view vulnerability findings.
  • Additional permissions may be required to modify Defender for Cloud plans or resource settings.

Use least privilege and avoid granting broad subscription-wide permissions unnecessarily.


13. Microsoft Defender for Endpoint Integration

Defender for Endpoint is the primary endpoint protection and EDR integration used by Defender for Servers.

The integration can provide:

  • Antivirus
  • Antimalware protection
  • Endpoint detection and response
  • Behavioral detection
  • Threat intelligence
  • Automated investigation and response
  • Threat hunting
  • Attack surface reduction
  • Security alerts
  • Vulnerability information
  • Software inventory

When Defender for Servers is enabled, Defender for Endpoint integration is enabled by default in supported configurations. Defender for Cloud can automatically provision the Defender for Endpoint sensor on supported machines.

EDR Data Flow

Protected server
|
v
Microsoft Defender for Endpoint sensor
|
v
Microsoft Defender for Endpoint service
|
v
Microsoft Defender for Cloud
|
+--> Security recommendations
+--> Security alerts
+--> Vulnerability findings
+--> Incident investigation
|
v
Microsoft Sentinel, when integrated

Security teams can review alerts in Defender for Cloud and pivot to the Microsoft Defender portal for deeper investigation and response.


14. Configuring Endpoint Protection

Endpoint protection settings are configured within the Defender for Servers plan settings.

Administrators should verify:

  • Defender for Endpoint integration is enabled.
  • The server is supported.
  • The endpoint sensor is installed.
  • The sensor is healthy.
  • Antivirus is enabled.
  • Security intelligence is current.
  • The machine is reporting to the correct tenant.
  • Conflicting endpoint security products are not preventing operation.
  • Required network endpoints are reachable.

Important Distinction

Enabling Defender for Servers does not guarantee that every machine is healthy immediately.

A server can be:

  • Connected to Azure Arc but missing Defender for Endpoint
  • Onboarded to Defender for Endpoint but not reporting correctly
  • Reporting EDR alerts but missing vulnerability data
  • Protected by antivirus but failing security configuration checks
  • Covered by Defender for Cloud but excluded from a specific feature

Protection status must be verified at the machine level.


15. Assessing EDR Configuration

Defender for Cloud can assess whether Defender for Endpoint is configured correctly.

Examples of EDR configuration checks include:

  • Antivirus is disabled or only partially configured.
  • Antivirus signatures are outdated.
  • Full or quick scans have not run recently.
  • Endpoint protection settings are incomplete.
  • The EDR solution is not functioning as expected.

Defender for Cloud can generate recommendations such as:

  • Resolve EDR configuration issues.
  • Enable or correctly configure antivirus.
  • Update outdated antivirus signatures.
  • Run required endpoint scans.

These checks help identify machines that technically have an EDR product installed but are not adequately protected.


16. EDR and Non-Microsoft Endpoint Products

An organization may already use a non-Microsoft EDR product.

In that situation, the organization should evaluate:

  • Whether Defender for Endpoint can coexist with the existing product
  • Whether the existing product must be removed
  • Whether passive or limited Defender for Endpoint modes are supported
  • Whether agentless scanning can provide vulnerability visibility
  • Whether the desired Defender for Servers features require Defender for Endpoint
  • Whether the existing EDR product provides equivalent capabilities

Agentless scanning can be useful for supported cloud machines when another EDR solution is installed. However, agentless scanning does not replace the full detection and response capabilities of Defender for Endpoint.


17. File Integrity Monitoring

File Integrity Monitoring, available with Defender for Servers Plan 2, helps identify changes to important files and registry settings.

It can help detect:

  • Unauthorized configuration changes
  • Changes to critical system files
  • Changes to security settings
  • Suspicious modifications
  • Potential persistence mechanisms
  • Changes that may indicate compromise

File Integrity Monitoring requires additional configuration after enabling Plan 2 and generally requires a Log Analytics workspace.

Administrators should identify:

  • Critical files
  • Critical directories
  • Important registry paths
  • Appropriate monitoring rules
  • Alerting requirements
  • Retention requirements

File Integrity Monitoring is not the same as a full backup solution. It identifies changes; it does not automatically restore files to a previous state.


18. Operating-System Security Configuration Assessment

Defender for Servers Plan 2 can assess operating-system configuration against supported security baselines.

Examples include:

  • Password policy
  • Security options
  • Services
  • Registry settings
  • File permissions
  • Operating-system security configuration
  • Other baseline settings

Some assessments require the Azure Policy machine configuration extension.

Machine Configuration can evaluate and, in supported scenarios, enforce settings inside the operating system.

Difference Between Defender Recommendations and Machine Configuration

  • Defender for Cloud recommendations identify security weaknesses.
  • Machine Configuration evaluates and can enforce specific configuration settings.
  • Azure Policy governs Azure resources and can assign or deploy configuration requirements.

These capabilities work together but are not interchangeable.


19. Data Collection and Log Analytics

Some Defender for Servers features require data collection through supported monitoring methods.

A Log Analytics workspace may be required for:

  • File Integrity Monitoring
  • Certain Plan 2 data-ingestion benefits
  • Supported monitoring and security data collection

When Plan 2 is enabled, eligible data types may receive a free daily ingestion benefit, subject to the current requirements and supported collection methods.

The benefit does not mean that all Log Analytics ingestion is free. It applies only to eligible data types and supported configurations.

Verify the Following

  • The machine reports to the intended workspace.
  • The appropriate data collection rule is configured.
  • Azure Monitor Agent is installed where required.
  • The workspace is in an appropriate region.
  • Data is actually arriving.
  • Retention and cost settings are appropriate.
  • Security data is not being collected unnecessarily.

20. Security Recommendations and Remediation

Defender for Cloud can generate recommendations for issues such as:

  • Defender for Endpoint is not installed.
  • Antivirus is disabled.
  • Vulnerability assessment is missing.
  • Vulnerable software is installed.
  • Security updates are missing.
  • EDR configuration is incomplete.
  • The server is not connected to Azure Arc.
  • Required extensions are missing.
  • Security configuration does not meet the baseline.
  • File Integrity Monitoring is not configured.

Recommendations can be remediated by:

  • Installing required agents
  • Enabling Defender for Servers
  • Updating software
  • Applying security configurations
  • Enabling antivirus
  • Correcting network access
  • Deploying extensions
  • Assigning appropriate policies
  • Reconfiguring the machine

A recommendation is not necessarily proof of an active attack. It usually indicates a security weakness or missing control.


21. Monitoring Protection Coverage

Defender for Cloud provides coverage information that helps identify:

  • Protected machines
  • Unprotected machines
  • Machines with incomplete onboarding
  • Machines missing required agents
  • Machines with unhealthy extensions
  • Machines without vulnerability assessment
  • Machines without EDR
  • Machines excluded from protection

Use coverage information to verify that the intended machines are actually protected.

A successful Arc connection alone does not prove that Defender for Servers, Defender for Endpoint, and vulnerability scanning are all functioning.


22. Troubleshooting Defender for Servers

The Server Is Missing from Defender for Cloud

Check:

  • Azure Arc connection status
  • Subscription and resource group
  • Onboarding credentials
  • Agent installation
  • Operating-system support
  • Network connectivity
  • Azure permissions
  • Resource provider registration

Defender for Endpoint Is Missing

Check:

  • Defender for Servers plan
  • Defender for Endpoint integration
  • Extension provisioning
  • Operating-system support
  • Proxy configuration
  • Firewall rules
  • TLS inspection
  • Existing endpoint security software
  • Local administrative permissions

Vulnerability Findings Are Missing

Check:

  • Whether vulnerability scanning is enabled
  • Whether the selected plan supports the desired scanning method
  • Whether the Defender for Endpoint sensor is healthy
  • Whether agentless scanning is supported
  • Whether a partner scanner is being used
  • Whether the initial scan has completed
  • Whether the machine is reporting current data

EDR Recommendations Appear

Check:

  • Antivirus status
  • Signature update status
  • Recent scan activity
  • Defender for Endpoint sensor health
  • Security policy configuration
  • Whether the machine is reporting to the correct tenant

File Integrity Monitoring Is Not Working

Check:

  • Defender for Servers Plan 2
  • Log Analytics workspace
  • Required monitoring configuration
  • Data collection rules
  • Azure Monitor Agent
  • Workspace connectivity
  • Monitored file and registry paths

23. Best Practices

Select the Plan Based on Requirements

Use Plan 1 when the primary need is endpoint protection and EDR.

Use Plan 2 when the organization requires advanced capabilities such as:

  • Agentless scanning
  • File Integrity Monitoring
  • Advanced vulnerability management
  • Security baseline assessment
  • Agentless secret or malware scanning
  • Additional server posture capabilities

Enable at the Appropriate Scope

Prefer subscription-level enablement for consistent coverage, but use resource-level controls when the deployment requires exceptions or phased adoption.

Use Azure Arc for Non-Azure Servers

Use Azure Arc-enabled servers for on-premises, AWS, and GCP servers when the organization needs the broadest supported Defender for Servers functionality.

Verify Protection, Not Just Enrollment

After onboarding, verify:

  • Arc connection
  • Defender for Endpoint status
  • Vulnerability scanning
  • Security recommendations
  • EDR alerts
  • Extension health
  • Data collection
  • Policy compliance

Use Least Privilege

Restrict access to:

  • Defender for Cloud configuration
  • Defender for Endpoint administration
  • Extension deployment
  • Vulnerability assessment configuration
  • Log Analytics workspaces
  • Resource groups and subscriptions

Avoid Duplicate Scanners

If a partner vulnerability scanner is already deployed, determine whether it should remain the authoritative scanner or whether Defender Vulnerability Management should be used.

Keep Security Components Updated

Maintain:

  • Operating-system updates
  • Defender for Endpoint sensor
  • Azure Connected Machine agent
  • Azure Monitor Agent
  • Security extensions
  • Vulnerability-scanning components

24. Key Exam Takeaways

  1. Defender for Servers Plan 1 focuses primarily on endpoint protection and EDR.
  2. Plan 2 includes Plan 1 capabilities plus advanced posture, scanning, and monitoring features.
  3. Agent-based vulnerability scanning uses the Defender for Endpoint sensor.
  4. Agentless vulnerability scanning is available with Plan 2 for supported machines.
  5. Defender Vulnerability Management is integrated with Defender for Servers.
  6. Direct Defender for Endpoint onboarding is not equivalent to full Azure Arc onboarding.
  7. Azure Arc is generally required for the broadest Defender for Servers functionality on non-Azure servers.
  8. AWS and GCP accounts can be connected to Defender for Cloud through native multicloud connectors.
  9. Defender for Cloud can assess EDR configuration, including antivirus status, signatures, and scan activity.
  10. A machine can be connected to Azure Arc but still lack healthy Defender for Endpoint protection.
  11. File Integrity Monitoring requires Plan 2 and additional configuration.
  12. Some Plan 2 capabilities require a Log Analytics workspace.
  13. Vulnerability scanning results can come from Defender Vulnerability Management or a supported partner scanner.
  14. Always check feature support for the specific operating system and cloud environment.
  15. Subscription-level enablement is generally preferred for consistent coverage.

Practice Exam Questions

Question 1

An organization wants to protect Azure VMs with endpoint detection and response and antivirus capabilities, but it does not require advanced agentless scanning or File Integrity Monitoring.

Which Defender for Servers plan is the most appropriate starting point?

A. Defender for Servers Plan 1
B. Defender for Servers Plan 2
C. Defender for Storage
D. Defender for Containers

Answer: A

Explanation: Plan 1 focuses primarily on endpoint protection capabilities provided through the Microsoft Defender for Endpoint integration. Plan 2 is required for additional advanced capabilities such as agentless scanning and File Integrity Monitoring.


Question 2

A company wants to perform vulnerability assessments on supported AWS EC2 instances without installing a traditional vulnerability-scanning agent inside the operating system.

Which configuration should the company use?

A. Defender for Servers Plan 1 with Azure Bastion
B. Defender for Servers Plan 2 with agentless scanning
C. Microsoft Sentinel only
D. Azure Firewall Premium only

Answer: B

Explanation: Defender for Servers Plan 2 supports agentless vulnerability scanning for supported machines, including supported onboarded AWS machines.


Question 3

An administrator has enabled Defender for Servers Plan 1. The organization wants vulnerability information based on installed software and the Microsoft Defender for Endpoint sensor.

What should the administrator configure?

A. Agent-based vulnerability scanning through Defender for Endpoint
B. Azure Front Door
C. Azure Private Link
D. File Integrity Monitoring

Answer: A

Explanation: Agent-based vulnerability scanning uses the Defender for Endpoint sensor and is available with Defender for Servers Plan 1 or Plan 2 when the required integration is enabled.


Question 4

An on-premises server is directly onboarded to Microsoft Defender for Endpoint. The administrator expects all Defender for Servers Plan 2 features to be available.

What is the correct conclusion?

A. All Plan 2 features are available automatically.
B. Direct Defender for Endpoint onboarding provides no protection.
C. Some advanced Defender for Servers capabilities require Azure Arc onboarding.
D. Plan 2 is available only for Windows client devices.

Answer: C

Explanation: Direct Defender for Endpoint onboarding can provide endpoint protection and EDR, but some Defender for Servers capabilities require the machine to be onboarded through Azure Arc.


Question 5

Which capability is primarily responsible for endpoint detection and response in Defender for Servers?

A. Azure Resource Graph
B. Microsoft Defender for Endpoint
C. Azure Policy
D. Azure Backup

Answer: B

Explanation: Microsoft Defender for Endpoint provides endpoint protection and EDR capabilities that are integrated into Defender for Servers.


Question 6

Defender for Cloud reports that a server’s antivirus signatures are outdated and that recent scans have not been completed.

What type of issue is this?

A. An EDR configuration issue
B. An Azure subscription billing issue
C. A storage firewall issue
D. An Azure Arc resource-group issue

Answer: A

Explanation: Defender for Cloud can assess EDR configuration and identify issues such as outdated signatures, disabled antivirus, or missing recent scans.


Question 7

An organization wants to monitor unauthorized changes to critical files and registry settings on supported servers.

Which Defender for Servers capability should it configure?

A. Agentless secret scanning
B. File Integrity Monitoring
C. Azure Bastion
D. Azure DDoS Protection

Answer: B

Explanation: File Integrity Monitoring helps detect changes to monitored files and registry settings. It is available with Defender for Servers Plan 2 and requires additional configuration.


Question 8

An organization already uses a supported Qualys vulnerability scanner and wants its findings to appear in Defender for Cloud.

What should the organization use?

A. A supported partner vulnerability-assessment integration
B. Azure Bastion
C. Microsoft Sentinel automation rules only
D. Azure Firewall application rules

Answer: A

Explanation: Defender for Cloud supports partner vulnerability-assessment integrations, including supported Qualys and Rapid7 scenarios.


Question 9

A server is shown as connected in Azure Arc, but Defender for Endpoint alerts and vulnerability information are missing.

What should the administrator check first?

A. Whether Azure Front Door is deployed
B. Whether Defender for Servers is enabled and the required Defender for Endpoint components are healthy
C. Whether the server has an Azure public IP address
D. Whether Azure Bastion is configured

Answer: B

Explanation: An Azure Arc connection does not automatically prove that Defender for Servers and Defender for Endpoint are fully operational. The administrator should verify the plan, integration, extension status, and sensor health.


Question 10

An organization wants to assess operating-system security settings against supported security baselines on Arc-enabled servers.

Which combination is most appropriate?

A. Azure DNS and Azure Firewall
B. Microsoft Sentinel and Azure Bastion
C. Defender for Servers Plan 2 and supported machine-configuration capabilities
D. Azure Storage and Azure Backup

Answer: C

Explanation: Defender for Servers Plan 2 supports operating-system configuration assessment, and supported scenarios may require the Azure Policy machine configuration extension.


Go to the SC-500 Exam Prep Hub main page

Onboard servers to Defender for Servers in Defender for Cloud, including hybrid and multicloud scenarios (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for servers and virtual machines (VMs)
      --> Onboard servers to Defender for Servers in Defender for Cloud, including hybrid and multicloud scenarios


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Secure compute (20–25%) → Implement security for servers and virtual machines (VMs)

This topic focuses on how to onboard servers to Microsoft Defender for Servers through Microsoft Defender for Cloud, including servers running in:

  • Microsoft Azure
  • On-premises datacenters
  • Amazon Web Services (AWS)
  • Google Cloud Platform (GCP)
  • Other supported hybrid environments

The goal is to extend security posture management, vulnerability assessment, endpoint detection and response, and other workload protection capabilities beyond Azure.


1. What Is Microsoft Defender for Servers?

Microsoft Defender for Servers is a cloud workload protection plan in Microsoft Defender for Cloud that helps protect Windows and Linux servers and virtual machines.

It provides capabilities such as:

  • Security recommendations
  • Vulnerability assessment
  • Microsoft Defender for Endpoint integration
  • Endpoint detection and response (EDR)
  • Threat detection and investigation
  • File Integrity Monitoring
  • Agentless software inventory
  • Agentless secret scanning
  • Agentless malware scanning
  • Security configuration assessment
  • Regulatory compliance reporting
  • Just-in-time VM access in supported scenarios
  • Security posture visibility across hybrid and multicloud environments

Defender for Servers can protect servers running in Azure, on-premises environments, AWS, and GCP.

However, Defender for Servers does not replace operating-system hardening, patch management, identity security, network segmentation, or application security. It extends Microsoft’s security management and protection capabilities to supported servers.


2. Understanding the Main Components

Several services work together when protecting non-Azure servers.

Microsoft Defender for Cloud

Defender for Cloud provides:

  • Cloud security posture management
  • Security recommendations
  • Regulatory compliance dashboards
  • Workload protection plans
  • Security alerts
  • Centralized security visibility

Defender for Cloud is the primary management experience where you enable Defender for Servers and review recommendations and alerts.

Azure Arc-Enabled Servers

Azure Arc-enabled servers allows a physical or virtual server outside Azure to become an Azure resource.

After onboarding:

  • The server receives an Azure resource ID.
  • It can be placed in an Azure resource group.
  • Azure RBAC can be applied.
  • Azure Policy can evaluate the resource.
  • Azure extensions can be deployed.
  • Defender for Cloud can use the server as part of its protected server inventory.

Azure Arc provides the management connection between the external server and Azure.

Azure Connected Machine Agent

The Azure Connected Machine agent is installed on the server.

The agent:

  • Establishes the server’s relationship with Azure.
  • Communicates outbound to Azure.
  • Provides the Azure resource identity.
  • Enables supported extensions.
  • Allows Azure services to evaluate and manage the connected machine.
  • Helps Defender for Cloud deploy required security components.

Azure does not generally initiate inbound management connections into the customer’s network. The agent establishes outbound communication to Azure over encrypted connections.

Microsoft Defender for Endpoint

Defender for Servers integrates with Microsoft Defender for Endpoint to provide endpoint protection and EDR capabilities.

Defender for Endpoint can provide:

  • Antivirus and antimalware protection
  • Attack surface reduction
  • Threat detection
  • Behavioral analysis
  • Threat hunting
  • Automated investigation and response
  • Endpoint security alerts

Defender for Servers Plan 1 and Plan 2 provide Defender for Endpoint capabilities through the Defender for Cloud integration.


3. Defender for Servers Plan 1 and Plan 2

Defender for Servers provides two primary paid plans.

Plan 1

Plan 1 is the entry-level plan and focuses primarily on endpoint protection through Microsoft Defender for Endpoint integration.

Important capabilities include:

  • Microsoft Defender for Endpoint integration
  • Endpoint detection and response
  • Antivirus and antimalware capabilities
  • Threat detection and investigation
  • Attack surface reduction
  • Security recommendations

Plan 2

Plan 2 includes the capabilities of Plan 1 and adds advanced server protection and assessment capabilities.

Depending on the supported server type and scenario, Plan 2 can provide capabilities such as:

  • File Integrity Monitoring
  • Just-in-time VM access
  • Agentless scanning
  • Advanced vulnerability assessment
  • Agentless software inventory
  • Agentless secret scanning
  • Agentless malware scanning
  • Additional security posture assessments
  • System updates and patch-management capabilities

The exact feature availability depends on the operating system, cloud environment, onboarding method, and current Defender for Cloud support matrix.

Exam Tip

Do not assume that every Defender for Servers feature is available for every server type.

For example:

  • Some Azure VM features are not available for Arc-enabled servers.
  • Some features available for Azure VMs are not available for AWS or GCP machines.
  • Some Plan 2 capabilities require Azure Arc.
  • Direct Defender for Endpoint onboarding does not provide the complete set of Defender for Servers capabilities.

4. Azure VMs Versus Hybrid and Multicloud Servers

Azure Virtual Machines

Azure VMs are already Azure resources. Defender for Cloud can associate them directly with the subscription and resource group where they exist.

The onboarding process generally involves:

  1. Enable Defender for Servers for the subscription.
  2. Select Plan 1 or Plan 2.
  3. Configure the required agent or agentless capabilities.
  4. Verify that the VM is protected.

On-Premises Servers

On-premises servers should generally be onboarded as Azure Arc-enabled servers.

The server remains physically in the organization’s datacenter, but Azure represents it as a resource for management and security purposes.

AWS and GCP Servers

AWS and GCP environments can be connected to Defender for Cloud through native cloud connectors.

For complete server protection, AWS and GCP machines are generally onboarded as Azure Arc-enabled machines. Microsoft recommends onboarding AWS and GCP machines as Arc-enabled servers to take advantage of the full Defender for Servers capability set.


5. High-Level Onboarding Architecture

The typical hybrid or multicloud architecture is:

On-premises / AWS / GCP Server
|
| Azure Connected Machine agent
|
v
Azure Arc-enabled server
|
v
Microsoft Defender for Cloud
|
+--> Defender for Servers
|
+--> Microsoft Defender for Endpoint
|
+--> Vulnerability Assessment
|
+--> Azure Policy / Machine Configuration
|
+--> Azure Monitor / Log Analytics
|
+--> Microsoft Sentinel

The Azure Arc agent provides the connection, while Defender for Cloud provides the security management and protection experience.


6. Planning Before Onboarding

Before onboarding servers, plan the following.

Subscription and Resource Group Design

Decide:

  • Which Azure subscription will contain the connected servers
  • Which resource groups will be used
  • Whether servers should be grouped by environment, business unit, application, or ownership
  • Which administrators need access
  • Whether Tier 0 or highly sensitive servers require a dedicated subscription or resource group

Resource groups can be used to apply access control and organize servers according to operational responsibility.

Azure Region and Data Residency

The Azure region selected for Arc-enabled servers affects where resource metadata and certain security-related data are processed or stored.

Before onboarding, evaluate:

  • Regulatory requirements
  • Data residency requirements
  • Internal security policies
  • Cross-border data transfer restrictions
  • Log storage locations
  • Defender for Cloud and Defender for Endpoint data-handling requirements

CSPM capabilities are generally agentless, while workload protection capabilities can require agents and extensions. Therefore, data residency planning must consider both the Azure service and the agents deployed to the server.

Supported Operating Systems

Verify that the server’s:

  • Operating system
  • Version
  • Architecture
  • Installed dependencies
  • Network configuration

are supported by Azure Arc and Defender for Servers.

An unsupported operating system can prevent successful onboarding or limit available protection features.

Network Connectivity

The server must be able to communicate outbound to required Azure endpoints.

Review:

  • Firewall rules
  • Proxy configuration
  • DNS resolution
  • TLS inspection
  • Outbound port 443 access
  • Private endpoint requirements
  • AWS or GCP connector-specific endpoints

Most Arc communication is outbound and encrypted using TLS. Extensions may require additional endpoints beyond those required by the core Arc agent.


7. Required Permissions and Identity

Azure Permissions

The person or automation process performing onboarding needs sufficient permissions to:

  • Register or use the required resource providers
  • Create Azure Arc resources
  • Place resources in the target resource group
  • Enable Defender for Cloud plans
  • Configure extensions or related services

Use the principle of least privilege. Avoid granting subscription-wide Owner access when a narrower role is sufficient.

Onboarding Credentials

Onboarding credentials must be protected because they can be used to create or connect resources in Azure.

Best practices include:

  • Use a dedicated onboarding identity.
  • Use least-privilege permissions.
  • Avoid embedding credentials in scripts or source code.
  • Protect service principal secrets.
  • Rotate credentials regularly.
  • Prefer short-lived or federated authentication where supported.
  • Remove temporary onboarding permissions after deployment.
  • Store secrets in a secure secret-management service.

Local Server Permissions

Installing the Azure Connected Machine agent generally requires administrative privileges on the server.

After installation, the agent’s service model is designed to avoid requiring a permanently privileged domain service account. Microsoft documents different service-account behavior for Windows and Linux, and domain-joined service accounts or alternate user identities are not supported for the agent service model.


8. Onboarding On-Premises Servers

A typical on-premises onboarding process is:

Step 1: Prepare the Environment

Confirm:

  • Azure subscription availability
  • Target resource group
  • Azure region
  • Supported operating system
  • Required outbound connectivity
  • Appropriate Azure permissions
  • Defender for Cloud configuration

Step 2: Install the Azure Connected Machine Agent

Install the Azure Connected Machine agent on the server.

The agent can be installed:

  • Manually
  • Through scripted deployment
  • Through configuration-management tools
  • At scale using supported automation methods

Step 3: Authenticate the Machine

Use an approved onboarding method, such as:

  • Interactive authentication
  • Service principal authentication
  • Other supported automated authentication methods

The authentication method should be selected based on the scale of deployment and the organization’s identity-management standards.

Step 4: Connect the Server to Azure

After successful authentication, the server appears as an Azure Arc-enabled server.

It receives:

  • An Azure resource ID
  • A resource group association
  • A location
  • A managed identity
  • A connection status

Step 5: Enable Defender for Servers

Enable Defender for Servers for the subscription or appropriate scope.

Select Plan 1 or Plan 2 based on the required capabilities and licensing needs.

Step 6: Verify Protection

Verify:

  • The server appears in Defender for Cloud.
  • The Arc connection is healthy.
  • Defender for Endpoint is onboarded where required.
  • Vulnerability assessment is active.
  • Security recommendations are being generated.
  • Security alerts can be viewed.
  • Required extensions are provisioned successfully.

Microsoft provides a workflow for connecting on-premises machines to Defender for Cloud through Azure Arc and verifying the Defender for Endpoint integration.


9. Onboarding AWS Servers

AWS servers are generally connected through a native AWS connector in Defender for Cloud.

The process typically includes:

  1. Connect the AWS account to Defender for Cloud.
  2. Configure the required AWS IAM permissions.
  3. Select the subscriptions and regions to protect.
  4. Enable the appropriate Defender for Cloud plans.
  5. Configure Azure Arc onboarding for supported EC2 instances.
  6. Install or provision the Azure Connected Machine agent.
  7. Enable Defender for Servers.
  8. Verify security coverage.

AWS Systems Manager Agent can be used to help provision the Azure Arc agent automatically on supported AWS EC2 instances.

For full Defender for Servers functionality, AWS machines generally require:

  • Azure Arc agent
  • Microsoft Defender for Endpoint integration
  • Vulnerability assessment
  • Required agentless scanning capabilities
  • Appropriate AWS and Azure permissions
  • Required outbound network access

AWS and GCP server support is not identical. For example, some network-based security alerts and just-in-time access capabilities have different availability depending on the cloud platform.


10. Onboarding GCP Servers

GCP servers are connected through a native GCP connector in Defender for Cloud.

The process typically includes:

  1. Connect the GCP project to Defender for Cloud.
  2. Configure the required GCP permissions.
  3. Select the projects and resources to protect.
  4. Enable the required Defender for Cloud plans.
  5. Configure Azure Arc onboarding.
  6. Install or provision the Azure Connected Machine agent.
  7. Enable Defender for Servers.
  8. Verify that the server appears in Defender for Cloud.

The GCP OS Config agent can be used to help provision the Azure Arc agent automatically on supported Google Compute Engine instances.

Required components can include:

  • Azure Arc agent
  • Microsoft Defender for Endpoint
  • Vulnerability assessment
  • Agentless scanning
  • GCP IAM permissions
  • Required outbound network connectivity

GCP and AWS machines can both receive Defender for Servers protection, but feature support must be checked against the current support matrix.


11. Direct Defender for Endpoint Onboarding Versus Azure Arc

Some non-Azure servers can be onboarded directly to Microsoft Defender for Endpoint.

However, direct onboarding is not equivalent to onboarding through Azure Arc.

Direct Defender for Endpoint onboarding can provide endpoint protection and EDR capabilities, but some Defender for Servers Plan 2 capabilities still require Azure Arc.

Microsoft documents that directly onboarded servers receive Plan 1 capabilities and selected additional capabilities, while some Plan 2 features require Arc-enabled onboarding.

Use Azure Arc When You Need:

  • Azure resource representation
  • Azure RBAC
  • Azure Policy
  • Machine Configuration
  • Azure extensions
  • Defender for Servers capabilities that require Arc
  • Centralized hybrid and multicloud inventory
  • Azure management and governance
  • Integration with other Azure services

Use Direct Defender for Endpoint Onboarding When:

  • Endpoint protection is the primary requirement
  • Azure Arc is not appropriate for the scenario
  • The required Defender for Servers features do not depend on Arc
  • The organization wants direct EDR onboarding

For exam questions, carefully distinguish between Defender for Endpoint onboarding and Defender for Servers onboarding through Azure Arc.


12. Vulnerability Assessment

Defender for Servers can provide vulnerability assessment through supported capabilities, including:

  • Microsoft Defender Vulnerability Management
  • Integrated vulnerability assessment solutions
  • Agentless vulnerability scanning in supported scenarios

Vulnerability assessment helps identify:

  • Missing security updates
  • Vulnerable software
  • Unsupported software
  • Misconfigured applications
  • Security weaknesses that attackers could exploit

The assessment method depends on the server type, operating system, Defender for Servers plan, and current feature support.

Agent-Based Assessment

An agent-based solution runs on the server and can collect detailed information about software and vulnerabilities.

Agentless Assessment

Agentless assessment can analyze supported resources without installing a traditional scanning agent on the operating system.

Agentless capabilities may be available for:

  • Software inventory
  • Vulnerability assessment
  • Secret scanning
  • Malware scanning
  • Other supported assessments

Agentless features are not universally available across all operating systems and cloud environments.


13. Microsoft Defender for Endpoint Integration

Defender for Servers uses Microsoft Defender for Endpoint to provide endpoint protection.

The integration can provide:

  • Endpoint detection and response
  • Antivirus
  • Threat intelligence
  • Behavioral detections
  • Automated investigation and response
  • Threat hunting
  • Attack surface reduction
  • Security alerts

When Defender for Endpoint detects a threat, the alert can be surfaced in Defender for Cloud. Security teams can pivot to the Defender for Endpoint experience for deeper investigation.

This integration is particularly useful when an organization wants one endpoint security platform across Azure, on-premises, AWS, and GCP servers.


14. Security Recommendations and Compliance

After servers are connected, Defender for Cloud can evaluate their security posture.

Recommendations can address:

  • Missing operating-system updates
  • Weak security configurations
  • Missing endpoint protection
  • Vulnerable software
  • Unprotected servers
  • Insecure network configurations
  • Missing disk encryption
  • File integrity concerns
  • Security baseline deviations

Defender for Cloud can also provide regulatory compliance dashboards and reports.

The compliance dashboard does not automatically mean that the organization is compliant. It provides an assessment of how resources compare with selected regulatory standards and security controls.


15. Azure Policy and Machine Configuration

Azure Policy can be used to govern Arc-enabled servers.

Examples include:

  • Require specific tags.
  • Restrict allowed resource locations.
  • Audit whether servers are connected.
  • Audit security configuration.
  • Enforce configuration requirements.
  • Deploy required extensions.
  • Identify noncompliant machines.

Azure Machine Configuration, formerly associated with guest configuration, can evaluate and enforce settings inside supported servers.

Examples include:

  • Password policy settings
  • Security baseline settings
  • Required services
  • Registry settings
  • File permissions
  • Operating-system configuration
  • Compliance with organizational standards

Azure Policy evaluates the Azure resource and can use machine configuration to assess settings inside the operating system.

Important Security Consideration

Extensions can perform powerful operations on a connected machine. Therefore:

  • Restrict who can deploy extensions.
  • Use RBAC carefully.
  • Limit extension permissions.
  • Review inherited policy assignments.
  • Use local agent security controls where stronger restrictions are required.

For highly sensitive or Tier 0 servers, Microsoft recommends stronger isolation, dedicated subscriptions, limited persistent administration, and careful review of inherited access and policies.


16. Network Requirements

The Azure Connected Machine agent normally communicates outbound to Azure.

Common requirements include:

  • DNS resolution
  • Outbound HTTPS connectivity
  • Port 443 access
  • Access to required Azure endpoints
  • Proxy configuration when applicable
  • Trusted TLS certificates
  • Firewall allowlists

For AWS and GCP deployments, additional cloud-specific endpoints may be required.

TLS Inspection

TLS inspection can work if:

  • The server trusts the inspection certificate.
  • The inspection device does not interfere with the connection.
  • Required extensions do not use certificate pinning.

Some extensions may use certificate pinning, which can cause failures when traffic is intercepted or modified.

Private Endpoints

Private endpoints can be used for supported scenarios to restrict traffic paths.

However:

  • Not every Arc endpoint supports private endpoints.
  • Microsoft Entra ID may still require firewall exceptions.
  • SSH and Windows Admin Center access over a private endpoint are not automatically supported by the Arc connection.
  • Extension-specific connectivity requirements may remain.

17. Monitoring and Logging

Defender for Servers should be monitored after onboarding.

Check:

  • Arc agent connection status
  • Last heartbeat
  • Defender for Endpoint health
  • Extension provisioning status
  • Vulnerability assessment status
  • Policy compliance
  • Security recommendations
  • Security alerts
  • Log ingestion
  • Data collection configuration

Azure Monitor and Log Analytics can be used for supported monitoring and logging scenarios.

Microsoft Sentinel can provide centralized security information and event management across:

  • Azure
  • On-premises servers
  • AWS
  • GCP
  • Microsoft Defender for Cloud
  • Microsoft Defender for Endpoint
  • Other security products

Defender for Cloud integrates with Microsoft Sentinel so that security alerts can be centralized for investigation, correlation, and automated response.


18. Common Onboarding Problems

Problem 1: The Server Does Not Appear in Azure

Possible causes include:

  • Invalid onboarding credentials
  • Insufficient Azure permissions
  • Failed agent installation
  • Unsupported operating system
  • Blocked outbound connectivity
  • Incorrect subscription or resource group
  • Failed authentication

Problem 2: The Arc Agent Is Connected but Defender for Servers Is Not Active

Possible causes include:

  • Defender for Servers is not enabled for the correct subscription.
  • The server is associated with a different subscription.
  • The required plan has not been selected.
  • The Defender for Endpoint extension failed.
  • The server is not supported for the selected capability.
  • Licensing or provisioning has not completed.

Problem 3: Defender for Endpoint Is Not Onboarded

Check:

  • Extension provisioning status
  • Operating-system support
  • Outbound connectivity
  • Proxy and TLS inspection
  • Defender for Endpoint licensing
  • Conflicting endpoint security software
  • Local administrative permissions

Problem 4: Vulnerability Data Is Missing

Possible causes include:

  • Vulnerability assessment is not enabled.
  • The required agent or extension failed.
  • The server is not supported.
  • The assessment has not completed its initial scan.
  • Network access is blocked.
  • The selected Defender for Servers plan does not include the required capability.

Problem 5: Policy Reports Noncompliance

Possible causes include:

  • The server does not meet the assigned configuration.
  • The policy assignment is inherited.
  • The machine configuration extension is missing.
  • The policy has not evaluated recently.
  • The server is disconnected.
  • The policy definition does not support the operating system.

19. Best Practices

Use a Standardized Onboarding Process

Create a repeatable process that includes:

  1. Inventory the server.
  2. Confirm support.
  3. Assign the target subscription and resource group.
  4. Validate network access.
  5. Use least-privilege onboarding credentials.
  6. Install the Arc agent.
  7. Enable Defender for Servers.
  8. Verify protection.
  9. Apply policies and security baselines.
  10. Monitor the server continuously.

Onboard at Scale

For large environments, use:

  • Automation
  • Infrastructure as code
  • Configuration-management tools
  • AWS Systems Manager
  • GCP OS Config
  • Standardized deployment scripts
  • Centralized policy assignments

Protect Onboarding Credentials

Do not store service principal secrets in:

  • Source code
  • Public repositories
  • Unencrypted scripts
  • Shared documents
  • Local administrator profiles

Restrict Administrative Access

Use:

  • Azure RBAC
  • Privileged Identity Management
  • Just-in-time access where supported
  • Separate administrator roles
  • Dedicated subscriptions for sensitive resources
  • Resource-group-level permissions

Monitor Agent and Extension Health

A connected server is not necessarily a fully protected server. Confirm that the required security extensions and Defender for Endpoint components are installed and healthy.

Validate Feature Availability

Always verify whether a feature is supported for:

  • Azure VMs
  • Arc-enabled servers
  • AWS machines
  • GCP machines
  • Windows
  • Linux
  • Plan 1
  • Plan 2

20. Key Exam Takeaways

Remember these points:

  1. Defender for Servers protects supported Windows and Linux servers across Azure, on-premises, AWS, and GCP.
  2. Azure Arc is the primary connection method for non-Azure servers when full Defender for Servers capabilities are required.
  3. The Azure Connected Machine agent establishes the server’s relationship with Azure.
  4. Azure Arc-enabled servers become Azure resources with resource IDs and resource-group placement.
  5. Defender for Endpoint provides core EDR capabilities.
  6. Plan 2 includes additional advanced capabilities, but feature availability varies by environment.
  7. Direct Defender for Endpoint onboarding is not equivalent to full Azure Arc onboarding.
  8. AWS and GCP connectors provide cloud-level visibility, while Arc enables deeper server-level protection.
  9. Azure Policy and Machine Configuration help govern and assess server configuration.
  10. Outbound network connectivity and endpoint allowlisting are essential.
  11. Onboarding credentials must be protected and assigned least-privilege permissions.
  12. A connected Arc server must still be monitored for agent, extension, Defender, and policy health.

Practice Exam Questions

Question 1

An organization has 200 Windows servers running in an on-premises datacenter. The organization wants to manage them through Azure and use Defender for Servers capabilities that require Azure resource representation.

What should the organization do?

A. Install only the Microsoft Defender Antivirus client on each server.
B. Onboard the servers as Azure Arc-enabled servers and enable Defender for Servers.
C. Move all servers into Azure Virtual Machines.
D. Connect the servers only to Microsoft Sentinel.

Answer: B

Explanation: Azure Arc-enabled servers allows on-premises servers to become Azure resources. Defender for Servers can then provide security posture and workload protection capabilities without requiring the servers to be moved into Azure.


Question 2

A company wants to protect AWS EC2 instances with Defender for Servers and obtain the broadest supported set of server protection capabilities.

Which component is generally required for the EC2 instances?

A. Azure Bastion
B. Azure Application Gateway
C. Azure VPN Gateway
D. Azure Arc-enabled servers

Answer: D

Explanation: AWS machines should generally be onboarded as Azure Arc-enabled servers to obtain the full set of supported Defender for Servers capabilities. Azure Arc provides the connection between the AWS machine and Azure.


Question 3

Which component establishes the relationship between a non-Azure server and Azure?

A. Azure Connected Machine agent
B. Microsoft Sentinel connector
C. Azure Firewall
D. Azure Resource Graph query

Answer: A

Explanation: The Azure Connected Machine agent is installed on the non-Azure server and establishes its connection to Azure Arc.


Question 4

An administrator directly onboards an on-premises server to Microsoft Defender for Endpoint. The administrator expects every Defender for Servers Plan 2 capability to become available.

Is this expectation correct?

A. Yes. Direct Defender for Endpoint onboarding always provides every Defender for Servers feature.
B. Yes, but only if the server is running Windows Server.
C. No. Some Defender for Servers capabilities still require Azure Arc onboarding.
D. No. Defender for Endpoint cannot protect on-premises servers.

Answer: C

Explanation: Direct Defender for Endpoint onboarding can provide endpoint protection and EDR, but some Defender for Servers Plan 2 capabilities require Azure Arc-enabled onboarding.


Question 5

An organization wants to evaluate security settings inside the operating system of Arc-enabled servers.

Which capability is most appropriate?

A. Azure Resource Graph only
B. Azure Machine Configuration
C. Azure DNS
D. Azure Front Door

Answer: B

Explanation: Azure Machine Configuration can evaluate and, in supported scenarios, enforce settings inside the operating system of Arc-enabled servers.


Question 6

Which network requirement is most commonly necessary for the Azure Connected Machine agent?

A. Inbound TCP port 3389 from Azure
B. Inbound TCP port 22 from Azure
C. Outbound HTTPS connectivity to required Azure endpoints
D. A public IP address assigned to every server

Answer: C

Explanation: Arc communication is generally outbound and encrypted over HTTPS. The server does not normally require inbound RDP or SSH access from Azure for the Arc connection.


Question 7

An organization connects its GCP project to Defender for Cloud. It wants server-level protection for supported Google Compute Engine instances.

What should it plan to deploy?

A. Azure Arc agent and the required Defender for Servers components
B. Azure Bastion on every GCP VM
C. Azure Application Gateway in the GCP project
D. Azure VPN Gateway on every GCP VM

Answer: A

Explanation: The Azure Arc agent connects supported GCP machines to Azure and allows Defender for Cloud to deploy the extensions and components required for Defender for Servers.


Question 8

Which statement best describes the difference between Defender for Cloud CSPM and Defender for Servers workload protection?

A. CSPM always requires the Microsoft Defender for Endpoint agent.
B. Defender for Servers is only available for Azure VMs.
C. CSPM evaluates security posture, while Defender for Servers provides server workload protection and may require agents or extensions.
D. CSPM and Defender for Servers are identical capabilities with different names.

Answer: C

Explanation: CSPM focuses on security posture and can be agentless in multicloud scenarios. Defender for Servers provides workload protection capabilities that can require Azure Arc, Defender for Endpoint, vulnerability assessment, or other components.


Question 9

A server appears as connected in Azure Arc, but no Defender for Endpoint alerts or vulnerability information are appearing.

What should the administrator check first?

A. Whether Azure Front Door is enabled
B. Whether Defender for Servers is enabled for the correct subscription and the required extensions are healthy
C. Whether the server has an Azure public IP address
D. Whether Azure Bastion is deployed

Answer: B

Explanation: An Arc connection alone does not guarantee that Defender for Servers protection is active. The administrator should verify the Defender for Servers plan, subscription association, Defender for Endpoint provisioning, vulnerability assessment, and extension health.


Question 10

An organization is onboarding highly sensitive Tier 0 servers through Azure Arc. Which approach best follows security best practices?

A. Use a dedicated subscription, minimize persistent administrative access, and review inherited policies and permissions.
B. Grant all administrators the Owner role at the tenant root scope.
C. Allow unrestricted extension deployment by all resource users.
D. Store onboarding credentials in a shared script repository.

Answer: A

Explanation: Highly sensitive servers should be isolated where practical, managed using least privilege, and protected from unnecessary administrative access and uncontrolled extension deployment. Onboarding credentials should also be securely managed.


Go to the SC-500 Exam Prep Hub main page

Implement and manage agentless scanning for VMs in Defender for Servers (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for servers and virtual machines (VMs)
      --> Implement and manage agentless scanning for VMs in Defender for Servers


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Microsoft Defender for Servers is a workload protection plan in Microsoft Defender for Cloud that helps protect Windows and Linux servers running in:

  • Azure
  • Amazon Web Services
  • Google Cloud Platform
  • On-premises environments
  • Other environments connected through Azure Arc

One of its important capabilities is vulnerability assessment. Vulnerability assessment identifies operating-system and software weaknesses, outdated applications, missing security updates, and other conditions that could expose a server to attack.

Defender for Servers supports two primary vulnerability-scanning approaches:

  1. Agent-based scanning
  2. Agentless scanning

Understanding the difference between these approaches, when agentless scanning is available, how to enable it, and how its results are used is important for the SC-500 exam.


What Is Agentless Scanning?

Agentless scanning assesses a virtual machine without requiring a vulnerability-scanning agent to be installed inside the guest operating system.

Instead of depending entirely on an operating-system agent, agentless scanning uses cloud-level access and inspection capabilities to collect information about supported machines. This can include information about:

  • Operating-system configuration
  • Installed software
  • Vulnerable applications
  • Security posture
  • Machine configuration
  • Potential exposure to known vulnerabilities

Agentless scanning is particularly useful when:

  • Installing another agent is undesirable.
  • The organization already uses a different endpoint security product.
  • A machine cannot easily support an additional agent.
  • The organization wants broader visibility into machine posture.
  • The organization needs to assess supported cloud machines without relying exclusively on an in-guest sensor.

Agentless scanning is not a replacement for every endpoint security capability. It primarily improves assessment and visibility. It does not provide the same continuous in-guest detection and response functionality as Microsoft Defender for Endpoint.


Defender for Servers Plans

Agentless scanning is closely associated with Defender for Servers Plan 2.

Defender for Servers Plan 1

Plan 1 primarily provides core server protection capabilities, including integration with Microsoft Defender for Endpoint.

Important capabilities include:

  • Endpoint detection and response
  • Endpoint protection
  • Software inventory through the integrated endpoint security experience
  • Agent-based vulnerability assessment through Defender for Endpoint
  • Security recommendations and alerts in Defender for Cloud

Plan 1 does not provide the full set of Plan 2 agentless assessment capabilities.

Defender for Servers Plan 2

Plan 2 includes the capabilities of Plan 1 and adds more advanced server protection and assessment features, including:

  • Agentless machine scanning
  • Additional Microsoft Defender Vulnerability Management capabilities
  • Compliance and security posture assessment
  • Operating-system configuration assessment
  • Operating-system update assessment
  • File Integrity Monitoring
  • Additional malware and secrets-scanning capabilities in supported scenarios
  • Premium vulnerability-management capabilities

The exact capabilities available can vary by operating system, cloud environment, machine type, and supported integration. Therefore, an exam question may require checking not only the selected plan but also whether the machine and environment support the feature.

Microsoft documentation identifies agentless scanning as a Plan 2 capability, while agent-based scanning through Defender for Endpoint is available with both Plan 1 and Plan 2.


Agent-Based Versus Agentless Scanning

CharacteristicAgent-based scanningAgentless scanning
Requires an in-guest agentYesNo vulnerability-scanning agent is required
Common integrationMicrosoft Defender for EndpointDefender for Servers Plan 2 capabilities
Available with Plan 1Yes, through Defender for EndpointNo
Available with Plan 2YesYes
Provides endpoint detection and responseThrough Defender for EndpointNo
Useful when another EDR is installedMay create overlap or require careful planningOften useful for supported cloud machines
Data freshnessOften more continuous or currentDepends on collection and assessment process
CoverageDepends on sensor health and onboardingDepends on supported machine and cloud scenario
Primary valueIn-guest protection and vulnerability visibilityAgentless posture and vulnerability visibility

Agent-Based Scanning

Agent-based scanning uses the Microsoft Defender for Endpoint sensor. The sensor collects endpoint information and supports capabilities such as:

  • Endpoint detection and response
  • Software inventory
  • Vulnerability assessment
  • Threat detection
  • Security alerts
  • Investigation and response

Agent-based scanning is generally valuable when the organization wants continuous endpoint protection and detailed in-guest telemetry.

However, it requires the sensor to be installed, onboarded, supported, and healthy. If the sensor is missing or malfunctioning, vulnerability results may be incomplete or unavailable.

Agentless Scanning

Agentless scanning does not require the same in-guest vulnerability-scanning agent. It can provide vulnerability and posture information for supported machines, including some machines where another endpoint detection product is being used.

Agentless scanning is especially useful when:

  • The organization does not want to deploy the Defender for Endpoint sensor.
  • A third-party EDR is already installed.
  • The machine is a supported Azure virtual machine.
  • The organization needs additional visibility without modifying the guest operating system.

Agentless scanning does not eliminate all requirements. The machine must still be supported, within the correct Defender for Servers scope, and accessible through the required Azure or connected-cloud mechanisms.


Microsoft Defender Vulnerability Management

Defender for Servers integrates with Microsoft Defender Vulnerability Management, commonly abbreviated as MDVM.

MDVM helps organizations discover and prioritize weaknesses by using information such as:

  • Vulnerable software
  • Missing updates
  • Software versions
  • Known vulnerabilities
  • Exposure information
  • Security recommendations
  • Remediation priorities

The vulnerability data can be surfaced through the Microsoft Defender security experience and Microsoft Defender for Cloud.

The purpose is not simply to produce a list of Common Vulnerabilities and Exposures (CVEs). The broader goal is to help security teams determine:

  1. Which machines are vulnerable?
  2. Which applications are affected?
  3. How serious is the vulnerability?
  4. Is the vulnerable machine exposed?
  5. Which remediation should be performed first?
  6. Has the vulnerability been remediated?

Plan 2 provides access to additional premium Defender Vulnerability Management capabilities in supported scenarios. These may include advanced assessment and prioritization capabilities such as certificate assessment, security-baseline assessment, and other premium vulnerability-management features.


How Agentless Scanning Works

At a high level, the process is:

  1. Defender for Servers Plan 2 is enabled for the appropriate scope.
  2. Agentless scanning is enabled or remains enabled by default.
  3. Defender for Cloud identifies supported machines within that scope.
  4. Cloud-level assessment mechanisms collect supported machine information.
  5. Defender Vulnerability Management analyzes the collected information.
  6. Vulnerabilities and recommendations are displayed in Defender for Cloud and related Defender experiences.
  7. Administrators remediate the findings.
  8. The environment is rescanned or reassessed to confirm improvement.

Agentless scanning is an assessment capability. It does not automatically install operating-system updates or repair every vulnerability.

For example, if an agentless scan identifies an outdated version of an application, the scan reports the issue. The organization must still:

  • Update the application.
  • Remove the application.
  • Change the configuration.
  • Replace the virtual machine.
  • Apply a compensating control.
  • Accept or formally mitigate the risk.

Enabling Defender for Servers

Defender for Servers is enabled from the environment settings in Microsoft Defender for Cloud.

A typical portal workflow is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the relevant:
    • Azure subscription
    • AWS account
    • GCP project
  4. Select Defender plans.
  5. Locate Servers.
  6. Turn the plan on.
  7. Select Plan 1 or Plan 2.
  8. Save the configuration.

The portal may default to a particular plan depending on the current experience. Always verify that the selected plan is the one required by the scenario.

For agentless scanning, the relevant environment must use Defender for Servers Plan 2. Vulnerability assessment is enabled by default when Defender for Servers Plan 1 or Plan 2 is enabled, but the available scanning method depends on the selected plan and environment.

Recommended Scope

Microsoft recommends enabling Defender for Servers at the subscription level when possible.

Subscription-level enablement provides:

  • Consistent coverage
  • Easier administration
  • More predictable licensing
  • Centralized policy management
  • Fewer accidentally unprotected machines

Resource-level configuration can be used for exceptions, but it should be applied deliberately. Plan 2 cannot generally be enabled at the individual resource level in the same way as Plan 1; resource-level options may allow Plan 2 to be disabled where appropriate.


Configuring Vulnerability Assessment Settings

After enabling Defender for Servers, vulnerability-assessment settings can be configured from the Defender for Cloud environment settings.

A typical configuration path is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the subscription or connected environment.
  4. Open Defender for Servers.
  5. Locate the monitoring or configuration settings.
  6. Find Vulnerability assessment for machines.
  7. Select Edit configuration.
  8. Choose the required scanning configuration.
  9. Apply or save the changes.

Agentless scanning is enabled by default in supported Plan 2 scenarios. However, administrators should verify:

  • The correct plan is enabled.
  • The machine is in scope.
  • The operating system is supported.
  • The cloud environment is supported.
  • Required permissions are available.
  • Required connectivity and onboarding prerequisites are satisfied.
  • The machine is not excluded by policy or resource-level settings.

Microsoft documentation indicates that agentless scanning is available with Plan 2 and is enabled by default in supported Plan 2 or Defender CSPM scenarios.


Agentless Scanning and Defender CSPM

Agentless scanning can also be available through Defender CSPM, depending on the supported scenario.

Defender CSPM provides cloud security posture management capabilities, while Defender for Servers provides workload protection for servers.

The two services can overlap in certain assessment capabilities. When troubleshooting or designing a solution, determine whether the capability is being provided by:

  • Defender for Servers Plan 2
  • Defender CSPM
  • Defender for Endpoint
  • Another integrated vulnerability scanner

Do not assume that enabling one plan automatically provides every feature for every machine type.


What Happens When Both Agent-Based and Agentless Scanning Are Available?

In some environments, a machine may be assessed through more than one method.

When both agent-based and agentless results are available, Defender for Cloud generally prioritizes the agent-based results because they are expected to provide fresher endpoint information.

This is important because an agent-based sensor may have more current knowledge of:

  • Installed software
  • Running processes
  • Software changes
  • Endpoint configuration
  • Recently remediated vulnerabilities

Agentless results can still be valuable, particularly for machines without a healthy agent or for supported machines where agentless coverage is intentionally used.

The important exam concept is:

Agentless scanning expands coverage, but agent-based results may take precedence when both methods are available.


Using Third-Party Vulnerability Scanners

Organizations may already use a third-party vulnerability-management product, such as Qualys or Rapid7.

Defender for Servers supports certain bring-your-own-license, or BYOL, vulnerability-assessment integrations.

When a third-party scanner is configured:

  • The partner scanner may provide the primary vulnerability results.
  • Defender for Cloud can display the partner’s findings.
  • Agentless scanning may still help assess machines that do not have the partner agent or do not have complete partner findings.
  • Results and precedence depend on the configured scanner and supported integration.

Avoid deploying multiple vulnerability scanners without a clear design. Multiple scanners can create:

  • Duplicate findings
  • Conflicting severity values
  • Increased resource consumption
  • Confusing remediation ownership
  • Unclear source-of-truth decisions

A good design should identify:

  • Which scanner is authoritative
  • Which machines are covered by each scanner
  • How duplicate findings are handled
  • Which team owns remediation
  • How exceptions are documented

Agentless Scanning in Hybrid and Multicloud Environments

Defender for Servers supports more than Azure virtual machines.

Azure Virtual Machines

Azure VMs can be protected through the Azure subscription where Defender for Servers is enabled.

The VM must be:

  • In the correct subscription
  • Supported by the selected plan
  • Running a supported operating system
  • Included in the relevant monitoring scope

AWS and GCP

AWS accounts and GCP projects can be connected to Defender for Cloud.

The recommended approach generally uses Azure Arc-enabled servers to represent and manage connected machines. This provides a consistent Azure control-plane experience for security assessment and management.

The general process is:

  1. Connect the AWS account or GCP project to Defender for Cloud.
  2. Enable the required Defender plan.
  3. Onboard supported machines through the connected-cloud integration.
  4. Verify that the machines appear in Defender for Cloud.
  5. Confirm that the required protection and assessment capabilities are active.

On-Premises Servers

For on-premises servers, Azure Arc is recommended when full Defender for Servers functionality is required.

Directly installing Microsoft Defender for Endpoint on an on-premises machine can provide Plan 1-style endpoint protection functionality. However, it does not necessarily provide the complete set of Defender for Servers Plan 2 capabilities.

For example, under certain scenarios, Plan 2 adds premium vulnerability-management features beyond the basic Defender for Endpoint functionality, but the full set of Plan 2 capabilities requires the supported Defender for Cloud and Azure Arc integration.

The key exam distinction is:

Azure Arc is the preferred connection mechanism for obtaining the broadest Defender for Servers capabilities on non-Azure and on-premises servers.


Permissions

Proper permissions are required to configure and view vulnerability assessment.

A common permission distinction is:

  • Owner at the resource-group level may be required to deploy or configure the scanner.
  • Security Reader can view security findings and recommendations but does not have permission to make configuration changes.

The exact permissions depend on the operation being performed. For example:

  • Viewing recommendations
  • Enabling a Defender plan
  • Changing monitoring settings
  • Deploying required extensions
  • Configuring a workspace
  • Remediating a recommendation

These may require different roles.

Use least privilege rather than assigning Owner broadly to security analysts.


Relationship Between Agentless Scanning and EDR

Agentless scanning and endpoint detection and response serve different purposes.

Agentless Scanning

Agentless scanning focuses on assessment and visibility, such as:

  • Vulnerable software
  • Machine posture
  • Configuration weaknesses
  • Missing updates
  • Security recommendations

EDR

EDR is provided through Microsoft Defender for Endpoint and focuses on detecting and responding to threats on the endpoint.

EDR capabilities include:

  • Suspicious-process detection
  • Behavioral detection
  • Endpoint alerts
  • Investigation
  • Threat hunting
  • Automated response
  • Isolation and containment
  • Evidence collection

Agentless scanning does not replace EDR. A machine can have agentless vulnerability assessment and still require an endpoint protection and detection solution.


EDR Configuration Assessment

Defender for Cloud can assess certain endpoint protection and EDR-related configuration conditions in supported Plan 2 scenarios.

Recommendations may identify conditions such as:

  • Antivirus protection being disabled
  • Antivirus being partially configured
  • Outdated security intelligence
  • A full or quick scan not having run recently
  • Endpoint protection settings that do not meet expected requirements

These recommendations help identify machines that may technically have endpoint protection installed but are not adequately configured.

For example, a machine may have antivirus installed but still be at risk because:

  • Real-time protection is disabled.
  • Security signatures are outdated.
  • A required scan has not run.
  • The endpoint sensor is unhealthy.
  • The machine is not properly onboarded.

EDR configuration assessment should therefore be treated as a validation and hardening capability, not merely an installation check.


Log Analytics Requirements

Some Defender for Servers Plan 2 capabilities require a Log Analytics workspace or related data-collection configuration.

This is especially important for:

  • File Integrity Monitoring
  • Certain data-ingestion benefits
  • Supported security data collection
  • Some assessment and monitoring scenarios

Plan 2 may include a free daily data-ingestion benefit for eligible data, but the benefit is not automatic for every data source. The environment must be configured correctly, including the required workspace and supported collection mechanism.

For example, an organization may enable Plan 2 but still fail to receive the expected benefit because:

  • No Log Analytics workspace is configured.
  • The machine is not associated with the required workspace.
  • Azure Monitor Agent is not configured.
  • The required data collection rule is missing.
  • The collected data is not eligible for the benefit.

When troubleshooting, distinguish between:

  1. The Defender plan being enabled.
  2. The machine being onboarded.
  3. The required workspace existing.
  4. The correct agent or collection method being configured.
  5. The data actually being collected.

Monitoring and Validating Agentless Scanning

After enabling agentless scanning, validate the configuration rather than assuming it is working.

Check the following:

1. Plan Status

Confirm that Defender for Servers Plan 2 is enabled for the correct subscription or connected environment.

2. Machine Coverage

Verify that the target VM appears in Defender for Cloud and is not excluded by:

  • Resource-level settings
  • Azure Policy
  • Subscription configuration
  • Unsupported configuration
  • Scope filters

3. Operating-System Support

Confirm that the operating system and machine type are supported by the selected scanning method.

4. Scanning Configuration

Verify that agentless scanning is enabled where required.

5. Data Freshness

Check when vulnerability information was last updated. Old results may indicate:

  • Scanning has not completed.
  • The machine is not reachable through the required mechanism.
  • The machine is no longer active.
  • The assessment process is delayed.
  • The machine is not properly onboarded.

6. Agent Health

If agent-based scanning is also expected, verify the health and onboarding status of the Defender for Endpoint sensor.

7. Findings

Review:

  • Vulnerability severity
  • Affected software
  • Affected machines
  • Recommended remediation
  • Exposure information
  • Whether the finding is current or stale

Common Troubleshooting Scenarios

Scenario 1: The VM Does Not Appear as Protected

Possible causes include:

  • Defender for Servers is disabled.
  • The wrong subscription was selected.
  • The VM is excluded at the resource level.
  • The machine is unsupported.
  • The connected AWS or GCP environment is not configured correctly.
  • Azure Arc onboarding has not completed.

Scenario 2: No Vulnerability Results Are Available

Possible causes include:

  • Agentless scanning is not enabled.
  • The machine is not supported.
  • The machine is not in scope.
  • The scan has not completed.
  • Required permissions are missing.
  • Required connectivity is unavailable.
  • A third-party scanner is the configured source of results.
  • The Defender for Endpoint sensor is missing or unhealthy.
  • The machine is not properly onboarded.

Scenario 3: Agent-Based Results Are Missing

Check:

  • Defender for Endpoint onboarding
  • Sensor health
  • Supported operating system
  • Network connectivity
  • Licensing and plan configuration
  • Whether the machine is reporting to the expected Defender environment

Scenario 4: Agentless Scanning Is Expected but Unavailable

Check:

  • Whether Plan 2 is enabled
  • Whether the machine is a supported cloud or connected-server scenario
  • Whether the machine is connected through the required integration
  • Whether resource-level settings override subscription-level settings
  • Whether Defender CSPM or another scanner is providing the capability

Scenario 5: File Integrity Monitoring or Data-Ingestion Benefits Are Missing

Check:

  • Plan 2 status
  • Log Analytics workspace configuration
  • Azure Monitor Agent
  • Data collection rules
  • Machine association with the workspace
  • Eligibility of the collected data

Best Practices

Enable at the Correct Scope

Enable Defender for Servers at the subscription level where practical. Use resource-level exceptions only when there is a documented business or technical reason.

Use Azure Arc for Non-Azure Servers

Use Azure Arc to obtain a consistent management and security experience for on-premises, AWS, and GCP servers.

Avoid Unnecessary Scanner Duplication

If a third-party scanner is already deployed, decide whether it will remain authoritative or whether Defender Vulnerability Management will be used as the primary source.

Monitor Coverage Continuously

Do not assume that a one-time successful onboarding means the machine remains protected. Monitor:

  • Last-seen time
  • Agent health
  • Scan freshness
  • Coverage status
  • Security recommendations
  • EDR alerts

Separate Detection From Assessment

Use vulnerability assessment to identify weaknesses and EDR to detect and respond to active threats. Both capabilities may be required.

Use Least Privilege

Give administrators only the permissions required to configure plans, deploy extensions, view findings, or remediate issues.

Prioritize Findings

Prioritize vulnerabilities using more than CVSS severity alone. Consider:

  • Internet exposure
  • Exploit availability
  • Business criticality
  • Attack paths
  • Privileged access
  • Sensitive data
  • Compensating controls
  • Whether exploitation has been observed

Validate Prerequisites

Before enabling a feature, verify:

  • Plan
  • Scope
  • Supported operating system
  • Cloud environment
  • Arc status
  • Required permissions
  • Workspace requirements
  • Network connectivity
  • Existing scanner integrations

Exam-Focused Summary

Remember these key points:

  • Agentless scanning is primarily associated with Defender for Servers Plan 2.
  • Agent-based vulnerability scanning through Defender for Endpoint is available with Plan 1 and Plan 2.
  • Agentless scanning does not require the same in-guest vulnerability-scanning agent.
  • Agentless scanning does not replace EDR.
  • Defender for Endpoint provides endpoint detection and response.
  • Defender Vulnerability Management provides vulnerability and software assessment.
  • Azure Arc is recommended for full Defender for Servers functionality on non-Azure and on-premises servers.
  • AWS and GCP environments are connected through Defender for Cloud, generally with Arc-enabled machines.
  • When both scanning methods are available, agent-based results may take precedence because they are generally fresher.
  • Third-party scanners such as Qualys or Rapid7 may provide the primary vulnerability results when configured.
  • Scanning identifies vulnerabilities; it does not automatically patch every machine.
  • Plan 2 features may require Log Analytics, Azure Monitor Agent, or other prerequisites.
  • Security Reader can view findings, while configuration and deployment operations require additional permissions.

Practice Exam Questions

Question 1

An organization wants to assess supported Azure virtual machines for software vulnerabilities without installing a vulnerability-scanning agent inside the guest operating system. Which Defender for Servers plan should the organization select?

A. Defender for Servers Plan 1
B. Defender for Servers Plan 2
C. Microsoft Defender for Storage
D. Microsoft Defender for APIs

Answer: B

Explanation: Agentless scanning for supported machines is a Defender for Servers Plan 2 capability. Plan 1 provides core server protection and agent-based vulnerability assessment through Defender for Endpoint, but it does not provide the full Plan 2 agentless-scanning capability.


Question 2

A company uses a third-party endpoint detection and response product on its Azure virtual machines. The company wants vulnerability visibility without deploying the Microsoft Defender for Endpoint sensor to every machine. Which approach is most appropriate for supported machines?

A. Enable Defender for Servers Plan 2 and use agentless scanning
B. Enable only Defender for Servers Plan 1
C. Disable all endpoint protection products
D. Install Azure Bastion on every virtual machine

Answer: A

Explanation: Defender for Servers Plan 2 agentless scanning can provide vulnerability and posture visibility for supported machines without relying exclusively on the Microsoft Defender for Endpoint sensor. It does not replace the organization’s EDR solution.


Question 3

Where should an administrator normally begin when enabling Defender for Servers for an Azure subscription?

A. Azure Storage account networking settings
B. Microsoft Sentinel data connectors
C. Microsoft Defender for Cloud Environment settings
D. Microsoft Entra authentication methods

Answer: C

Explanation: Defender for Servers is enabled through Microsoft Defender for Cloud. The administrator selects Environment settings, chooses the subscription or connected environment, opens Defender plans, enables Servers, selects Plan 1 or Plan 2, and saves the configuration.


Question 4

An organization has on-premises Windows and Linux servers and wants the broadest supported Defender for Servers functionality, including cloud-based security management. What should the organization generally use to connect the servers?

A. Azure Bastion
B. Azure Arc-enabled servers
C. Azure Application Gateway
D. Microsoft Entra Domain Services

Answer: B

Explanation: Azure Arc is the recommended connection mechanism for on-premises and other non-Azure servers when the organization wants the broader Defender for Servers experience. Direct Defender for Endpoint onboarding can provide endpoint functionality, but it does not necessarily provide the full Defender for Servers Plan 2 experience.


Question 5

Which statement correctly describes the relationship between agent-based and agentless vulnerability scanning?

A. Agentless scanning always provides more current endpoint data than agent-based scanning
B. Agent-based scanning requires the Defender for Endpoint sensor, while agentless scanning does not require the same in-guest vulnerability-scanning agent
C. Agent-based scanning is available only with Defender for Servers Plan 2
D. Agentless scanning provides full endpoint detection and response

Answer: B

Explanation: Agent-based scanning uses the Defender for Endpoint sensor. Agentless scanning uses supported cloud-level assessment capabilities and does not require the same in-guest vulnerability-scanning agent. Agentless scanning does not provide full EDR functionality.


Question 6

A security administrator enables Defender for Servers Plan 2 but cannot find File Integrity Monitoring data for a VM. Which prerequisite should the administrator check first?

A. Whether the VM has an Azure public IP address
B. Whether Azure Bastion is deployed
C. Whether the VM is assigned a Microsoft Entra user
D. Whether the required Log Analytics workspace and data-collection configuration are present

Answer: D

Explanation: File Integrity Monitoring and certain Plan 2 data-ingestion capabilities require appropriate Log Analytics and data-collection configuration. The administrator should verify the workspace, Azure Monitor Agent, data collection rules, and machine association.


Question 7

An organization has configured a supported third-party vulnerability scanner through a bring-your-own-license integration. What should administrators expect?

A. The third-party scanner may provide the primary vulnerability results
B. Defender for Servers automatically disables all third-party scanner results
C. Agentless scanning is available only with Plan 1
D. EDR alerts are converted into storage-account recommendations

Answer: A

Explanation: Supported third-party scanners, such as Qualys or Rapid7, may provide the primary vulnerability results when configured. Agentless scanning may still help cover supported machines without the partner agent or without complete partner findings.


Question 8

A security analyst needs to view vulnerability findings and recommendations but should not be able to change Defender for Servers configuration. Which role is most appropriate?

A. Owner
B. Contributor
C. Security Reader
D. Global Administrator

Answer: C

Explanation: Security Reader is intended for viewing security information, including recommendations and findings. Configuration and deployment operations generally require more permissions, such as Owner or another appropriately scoped administrative role.


Question 9

Defender for Cloud reports that a VM has an EDR configuration issue. Which condition could produce this type of recommendation?

A. The VM has no attached data disk
B. Antivirus protection is disabled or security signatures are outdated
C. The VM is located in a virtual network with a subnet
D. The VM has an Azure resource tag

Answer: B

Explanation: EDR and endpoint-protection configuration assessments can identify conditions such as disabled or partially configured antivirus protection, outdated signatures, or scans that have not run recently. These recommendations help identify machines that may have endpoint protection installed but are not adequately configured.


Question 10

A VM has both agent-based and agentless vulnerability results available. Which result is generally given precedence when both methods provide data?

A. Agent-based results, because they generally provide fresher endpoint information
B. Agentless results, because they always replace agent-based results
C. Results from Azure Bastion
D. Results from Microsoft Sentinel only

Answer: A

Explanation: When both methods are available, agent-based results are generally shown because they are expected to provide fresher endpoint information. Agentless scanning remains useful for expanding coverage and assessing supported machines that do not have a healthy or compatible agent.


Go to the SC-500 Exam Prep Hub main page