A large share of Plan 2 only works once your servers are onboarded to Azure Arc. Skip that work and the license still bills you for capabilities the estate cannot reach.
What Plan 1 gives you is endpoint detection and response on servers, wherever they happen to run. Plan 2 layers on agentless scanning for vulnerabilities, malware and secrets, plus file integrity monitoring, just-in-time access and baseline assessment. Read the documentation closely and several of those carry a footnote: applicable only to machines onboarded through Azure Arc. That footnote is the whole project. Arc is not an implementation detail, it is the prerequisite.

- Two plansPlan 1 EDR, Plan 2 adds twelve capabilities
- Azure, AWS, GCPPlus on-premises Windows and Linux
- AgentlessMost Plan 2 scanning needs no agent
- 30 day trialCannot be stopped, paused or extended
Seven factors that settle which plan fits, and what you will genuinely get from it.
Windows and Linux, across three clouds and on-premises
Coverage runs to Windows and Linux across Azure, Amazon Web Services, Google Cloud Platform and whatever is still sitting in your own building. American businesses rarely arrive at a tidy estate on purpose. An Azure migration, an acquisition that came with an AWS footprint, and a data center nobody ever got round to shutting down is the normal picture, and that one line about multicloud coverage is usually why the product lands on the evaluation list.
Plan 1 is endpoint detection and response, delivered automatically
The core of Plan 1 is the Defender for Endpoint integration and the detection and response it brings: automatic onboarding, alerts and incidents flowing into one place, software inventory discovered rather than declared, regulatory compliance assessment, and agent-based vulnerability scanning. If your servers are currently running conventional antivirus, that alone is a significant step up.
The agentless shift in Plan 2 rewrote how this gets deployed
Three agentless scanners sit in Plan 2, covering vulnerabilities, malware and secrets held on the machine. Alongside that, Microsoft has moved most plan features off the Log Analytics agent and the Azure Monitor Agent entirely, handing the work to agentless scanning and the Defender for Endpoint integration. If you remember this product as an agent deployment exercise, that memory is out of date.
Just-in-time access, file integrity monitoring and baselines
Three further capabilities arrive with Plan 2: just-in-time access to virtual machines on Azure and AWS, file integrity monitoring, and an assessment of operating system configuration against the compute security baselines published in the Microsoft Cloud Security Benchmark. Together they move the product across the line from detecting threats to managing posture, and between them they answer more audit findings than anything else in the plan.
Azure Arc is a dependency, not a nice to have
Read the feature table carefully, because it says this out loud. Operating system updates and baseline misconfiguration assessment apply only where a machine came in through Azure Arc. File integrity monitoring reaches AWS and GCP machines only when those machines were onboarded with Arc. For anything on-premises, the documentation is blunt: direct onboarding leaves you without full access to Plan 2.
Defender Experts for Servers, if you have no analysts
This is managed extended detection and response for server workloads. Microsoft analysts do the triage, run the investigation, contain what needs containing, and hand back with steps written out. Scope is every Plan 1 and Plan 2 alert whose detection source is Defender for Servers, on Windows and Linux, across Azure, AWS, GCP and on-premises. Two things to know before you plan around it: it carries its own price, and DNS alerts fall outside it.
A thirty day trial that cannot be paused
Turning a plan on begins a thirty day trial, and Microsoft is clear that it cannot be stopped, paused or extended once started. The advice to plan the evaluation in advance is not boilerplate. Somebody flipping it on during a slow week to take a look has just spent the clock, and a trial that opens a fortnight before a holiday period delivers roughly half the evaluation time it appears to offer.
Run Plan 2 without Arc and you have a half deployment. The missing pieces are listed in the vendor documentation.
Nothing about the Arc dependency is hidden. It sits in the published feature table for anyone to read, and ignoring it remains the number one reason these deployments return less than the business case promised.
- Two capabilities carry the same restriction: operating system updates, and baseline misconfiguration assessment measured against the Microsoft Cloud Security Benchmark. Both apply only where the machine arrived through Azure Arc.
- File integrity monitoring is shown as available on Azure, AWS and GCP, with a qualifier on two of those three. On AWS and GCP it only applies where the machine was onboarded through Azure Arc.
- Anything sitting in your own data center should be onboarded as an Azure Arc virtual machine. That is the vendor recommendation, and the reason is stated alongside it: connect those machines directly to Defender for Cloud and Plan 2 will not be fully available to them.
- Which leaves one workable order: Arc, then the plan. Do it the other way round and the first three months get spent explaining to whoever signed the business case why the capabilities in it have not appeared.
Four disciplines that keep a server protection project from returning half of what you paid for.
We scope the Azure Arc work before the plan decision
Three restrictions point the same way. Operating system updates and baseline misconfiguration assessment need Arc. File integrity monitoring on AWS and GCP needs Arc. Direct onboarding of on-premises machines falls short of full Plan 2 access. Put those together and Arc belongs at the top of the project plan, not on a list somebody picks up once the first two phases are done.
The estate gets divided rather than covered by a single blanket purchase
The controls are deliberately uneven. Plan 1 can be turned on and off per server. Plan 2 cannot be turned on per resource, but it can be turned off per resource. That asymmetry is something to design around rather than work around. A Plan 2 subscription with particular resources switched off produces a commercial outcome quite unlike an all-in decision, and the difference is worth modeling before you commit.
Secrets scanning findings get worked, because nobody is ready for what they say
Of everything in a first Plan 2 run, agentless machine secrets scanning produces the report people least want to read. Credentials sitting inside scripts. Keys written into configuration files. Connection strings on machines nobody has signed into since before the last reorganization. Each of those needs a named owner and a rotation plan agreed before the document goes anywhere near a wider distribution list.
We time the thirty day trial around an actual evaluation
Since the trial cannot be halted, suspended or extended once it begins, and the guidance says to plan ahead accordingly, we settle three questions before anyone touches the switch: what is being tested, who is going to look at the results, and which decision this evaluation exists to inform. Without those answers agreed, thirty days pass and nothing has been proven either way.
Six US situations where server protection needs modernizing.
A company with servers spread across three clouds and a data center
Windows and Linux are covered across Azure, AWS, GCP and your own data center. The recommended path has two parts. AWS accounts and GCP projects get connected to Defender for Cloud, and the plan can be switched on during that connection. Separately, the machines themselves get onboarded as Azure Arc virtual machines, which is what opens up the complete feature set rather than a subset of it.
A regulated firm with a file integrity monitoring requirement
It sits in Plan 2 and wants a Log Analytics workspace behind it, either one you already run or one created while configuring. On AWS and GCP it reaches only those machines onboarded through Azure Arc. When a PCI DSS assessor, a bank examiner or a framework requirement names file integrity monitoring by name, that stack of dependencies is your real project. The purchase order is the easy part.
An organization that has never scanned its servers for secrets
The agentless secrets scanner in Plan 2 goes looking for credentials left lying on your servers, and it finds them. Service account passwords hard-coded into scripts. Keys committed to configuration files. Connection strings in locations nobody can account for. More than any other output from this product, that report is what moves secrets management up the priority list.
An operator that cannot deploy agents everywhere
Anyone who evaluated this product a few years ago should look again, because the agent requirements changed. Most plan features no longer run on the Log Analytics agent or the Azure Monitor Agent at all, having been handed over to agentless machine scanning and the Defender for Endpoint integration. Where change control turns every agent rollout into a quarter of work, that shift removes most of the friction.
An organization with no server security analysts
Defender Experts for Servers puts Microsoft analysts on the front of your server alerts. They triage, investigate, contain and then hand back with the next steps written out. Proactive threat hunting is included, as is the ability to put a question about a specific incident to the Microsoft team. It carries its own commercial arrangement, and it requires either Plan 1 or Plan 2 with Defender for Endpoint already deployed.
A business trying to close down standing management access
Available on Azure and AWS under Plan 2, just-in-time access keeps management ports shut until somebody asks for them and the request is approved. Plenty of organizations have spent years trying and failing to close standing remote desktop and secure shell exposure, and their cyber insurance application asks about precisely that. This gets there without redesigning the network first.
How US organizations protect servers today.
| Feature | Defender for Servers Plan 2 with Arc | Traditional antivirus on servers | Inconsistent or unknown |
|---|---|---|---|
Endpoint detection and response on servers | Yes | No | No |
Vulnerability scanning without an agent | Yes | No | No |
Secrets found on machines | Yes | No | No |
Operating system baselines assessed | Yes, with Arc | No | No |
File integrity monitoring | Yes | Sometimes | No |
Just-in-time management access | Yes | No | No |
Covers AWS and GCP machines too | Yes | Separately | No |
Alerts correlate with the rest of the estate | Yes | No | No |
Regulatory compliance assessed continuously | Yes | No | No |
Answer to what is running on that server | Inventory | Guess | None |
Nineteen capabilities, and where each one applies.
Capability
Multicloud and hybrid support
- Plan 1
- Yes
- Plan 2
- Yes
- Where it applies
- Any machine connected to Defender for Cloud, whether it runs in Azure, AWS, GCP or your own racks
Capability
Defender for Endpoint automatic onboarding
- Plan 1
- Yes
- Plan 2
- Yes
- Where it applies
- All supported machines
Capability
Defender for Endpoint endpoint detection and response
- Plan 1
- Yes
- Plan 2
- Yes
- Where it applies
- Azure, AWS and GCP
Capability
Integrated alerts and incidents
- Plan 1
- Yes
- Plan 2
- Yes
- Where it applies
- Azure, AWS and GCP
Capability
Software inventory discovery
- Plan 1
- Yes
- Plan 2
- Yes
- Where it applies
- Azure, AWS and GCP
Capability
Regulatory compliance assessment
- Plan 1
- Yes
- Plan 2
- Yes
- Where it applies
- Different standards for different environments
Capability
Vulnerability scanning, agent based
- Plan 1
- Yes
- Plan 2
- Yes
- Where it applies
- Azure, AWS and GCP
Capability
Vulnerability scanning, agentless
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Azure, AWS and GCP
Capability
Defender for DNS alerts
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Azure, AWS and GCP
Capability
Threat detection at the Azure network layer
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Azure
Capability
Operating system system updates
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Only machines onboarded with Azure Arc
Capability
Baseline misconfigurations, Microsoft Cloud Security Benchmark
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Only machines onboarded with Azure Arc
Capability
Defender Vulnerability Management premium features
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Available in the Defender portal only
Capability
Malware scanning, agentless
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Azure, AWS and GCP
Capability
Machine secrets scanning, agentless
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Azure, AWS and GCP
Capability
File integrity monitoring
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- AWS and GCP machines only when onboarded with Azure Arc
Capability
Just-in-time virtual machine access
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Azure and AWS
Capability
Network map
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Azure
Capability
Free data ingestion, 500 MB per node per day
- Plan 1
- No
- Plan 2
- Yes
- Where it applies
- Needs one of the supported collection methods in place, Azure Monitor Agent among them
Five steps, and Arc comes before the plan.
- 1
Inventory the estate and its connection state
A count of Windows and Linux machines by location, Azure, AWS, GCP and on-premises, and a second count of how many are Arc-enabled today. That second number drives everything, because AWS and GCP machines should be onboarded as Azure Arc virtual machines to reach the full feature set, and on-premises machines connected directly rather than through Arc end up with limited Plan 2 access.
- 2
Decide the plan against the capabilities you need
Plan 1 covers endpoint detection and response and can be switched on or off server by server. Plan 2 brings the agentless scanners for vulnerabilities, malware and secrets, plus file integrity monitoring, just-in-time access, the network map and baseline assessment. It is enabled across the subscription, though individual resources can be excluded afterwards.
- 3
Do the Arc and prerequisite work first
Four pieces get put in place: Arc onboarding for every machine that needs an Arc-dependent feature, the Azure Policy machine configuration extension wherever baseline assessment against the Microsoft Cloud Security Benchmark is required, a Log Analytics workspace if file integrity monitoring is in scope, and a supported collection method so the ingestion benefit is actually claimed.
- 4
Enable deliberately, with the trial clock in mind
Several things happen on their own here. The Defender for Endpoint extension installs itself on supported machines, vulnerability management comes on by default wherever that extension lands, and Plan 2 turns agentless scanning on without being asked. What does not happen on its own is the evaluation. The thirty day trial begins immediately and cannot be paused, so the criteria and the named people assessing them are agreed in advance.
- 5
Work the findings and decide the operating model
Someone takes ownership of the secrets findings and rotates them. Baseline misconfigurations get ranked rather than listed. Just-in-time access goes onto the machines still carrying open management ports. After that come the standing questions: who works the alerts day to day, whether Defender Experts for Servers is the answer where that capacity does not exist, and who is accountable for closing posture recommendations from here on.
What US organizations ask about Defender for Servers.
Fifteen checks that prevent a partial deployment.
Estate reality
- How many servers, and where?Azure, AWS, GCP, on-premises.
- How many are Windows and how many Linux?Both are supported.
- Are AWS accounts and GCP projects connected?That is the onboarding path.
- Are on-premises machines Arc-enabled?Direct onboarding limits Plan 2 features.
- Which servers genuinely need Plan 2?Plan 1 can be enabled per resource.
Prerequisites
- Is Azure Arc deployment scoped and funded?Several Plan 2 features depend on it.
- Is the machine configuration extension deployed?Required for OS baseline assessment.
- Do you have a Log Analytics workspace?Needed for file integrity monitoring.
- Is a supported collection method in place?For the 500 MB ingestion benefit.
- Is Defender for Endpoint already deployed?Required for Defender Experts for Servers.
After enabling
- Is the 30 day trial timed deliberately?It cannot be stopped, paused or extended.
- Do you want automatic provisioning on?The extension installs automatically by default.
- Who works the alerts?Or is Defender Experts for Servers in scope.
- Who owns remediation of the recommendations?Posture findings need an owner.
- Which resources should be excluded?Plan 2 can be disabled per resource.
The pages around this one.
Work out what proportion of your servers are Arc connected today. That single figure drives the schedule.
The capabilities that usually justify buying Plan 2 in the first place are documented as applying only to Arc-onboarded machines. Getting that count on the table at the start is what separates a deployment that delivers from one that spends its first quarter making excuses.
Related Services
Explore more solutions that work great with this service
Microsoft Defender for Cloud Services
Defender for Cloud deployment for US organizations: enabling free
Learn moreMicrosoft Defender for Containers
Container and Kubernetes security for US organizations using Defender
Learn moreMicrosoft Defender for SQL
Defender for SQL deployment for US organizations: the full SQL estate
Learn moreMicrosoft Defender for Endpoint Services
EDR plan selection, onboarding and zero-gap AV migration
Learn moreMicrosoft Defender Vulnerability Management Services
Defender Vulnerability Management deployment for US organizations:
Learn moreMicrosoft Security Services
The Microsoft security stack deployed and managed end to end
Learn more