Microsoft Defender for Endpoint
Endpoint protection

Migrate servers from Microsoft Defender for Endpoint to Microsoft Defender for Servers

In brief

The article now links to prerequisites and machine-type migration steps, clarifies Defender for Endpoint integration opt-ins, and updates Azure Arc and multicloud connector guidance.

What Defender admins need to know

Administrators planning server migrations have clearer guidance for validating prerequisites and configuring required integrations.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.collection:

  • m365-security
  • tier2 ms.custom: migrationguides, msecd-doc-authoring-10141016 ms.date: 06/16/07/03/2026 appliesto:
    • Microsoft Defender for Endpoint Plan 1
    • Microsoft Defender for Endpoint Plan 2

Migrate servers from Microsoft Defender for Endpoint to Microsoft Defender for Servers

This article describes how to migrate your servers from Defender for Endpoint to Defender for Servers. Before you begin, review the prerequisites and migration steps for your server type.

Defender for Endpoint is an enterprise endpoint security platform designed to helpplatform. It helps organizations prevent, detect, investigate, and respond to advanced threats. TheWith a Defender for Endpoint for servers license enableslicense, you tocan onboard a server to Defender for Endpoint.

Defender for Servers is part of the Microsoft Defender for Cloud offering, a solution. Defender for Cloud provides cloud security posture management (CSPM) and cloud workload protection (CWP) that. It finds weak spots acrossin your cloud configuration. Defender for Cloud alsosetup and helps strengthen the overall security posture of your environment, and can protect workloads across multicloud and hybrid environments from evolving threats.environments.

While both Defender for Endpoint for servers and Defender for ServersBoth products offer server protection capabilities,protection, but Defender for Servers is our primary solution to protect servers.

How do I migrate my servers from Defender for Endpoint to Defender for Cloud?

If you have servers onboarded to Defender for Endpoint, the migration process varies dependingsteps depend on the machine type, but there'stype. However, all machines share a set of shared prerequisites. Defender for Cloud is a subscription-based service in the Microsoft Azure portal. Therefore,You must enable Defender for Cloud and underlying plans likea Defender for Servers Planplan (Plan 1 or Plan 2 need to be enabled2) on your Azure subscriptions.

Before you enable Defender for Cloud

  1. Enable a Defender for Servers plan on your subscription. In case you're using Defender for Servers Plan 2, make sure to also enable it on the Log Analytics workspace your machines are connected to. Enabling Defender for Servers Plan 2 on the Log Analytics workspace lets you use optional features, like File Integrity Monitoring.

  2. Make sure the Defender for Endpoint integration is enabled on your subscription. If you have preexisting Azure subscriptions, you might see one or both of the two opt-in buttons for Allow MDE access to EWACS data and Allow MDE Unified Agent for EWACS as shown in the following image:

    :::image type="content" source="media/mde-integration.png" alt-text="Screenshot that shows how to enable Defender for Endpoint integration." lightbox="media/mde-integration.png":::

    If you havesee either of these opt-in buttons in your environment, make sure to enable integration for both. On new subscriptions, both options are enabled by default, and youthe buttons don't see these buttons in your environment.appear.

  3. If you're planning plan to use Azure Arc, make surecheck that the connectivity requirements are met. Defender for Cloud requires all on-premises and non-Azure machines to be connected usingconnect through the Azure Arc agent. In addition, Azure Arc doesn't support allevery operating system that Defender for Endpoint supported operating systems.supports. For help with your planning process,help, see Azure Arc deployments.

  4. (Recommended) If you want to see vulnerability findings in Defender for Cloud, make sure to enable vulnerability assessment in Defender for Cloud.

If you're using Amazon Web Services (AWS) or Google Cloud Platform (GCP), follow these steps to migrate those VMs:

  1. Create a new multicloud connector on your subscription. For more information about this connector,To learn more, see AWS accounts or GCP projects.

  2. On your multicloudthe connector, enableturn on Defender for Servers onfor AWS connectors or GCP connectors.

  3. EnableTurn on autoprovisioning on the multicloud connector for the Azure Arc agent, the Defender for Endpoint extension, and Vulnerability Assessment. ForIf you use Defender for Servers Plan 2, enablealso turn on agentless machine scanning.

    :::image type="content" source="media/select-plans-aws-gcp.png" alt-text="Screenshot that shows how to enable autoprovisioning for Azure Arc agent." lightbox="media/select-plans-aws-gcp.png":::

ForTo learn more information,about multicloud support and onboarding non-Azure machines, see the following resources:Defender for Cloud's multicloud capabilities and Connect your non-Azure machines to Microsoft Defender for Cloud.

What happens once all migration steps are completed?

After you complete the relevant migration steps, Defender for Cloud deploys the Defender for Endpoint extension for Windows (MDE.Windows) or Linux (MDE.Linux) to your Azure VMs and Arc-connected non-Azure machines connected through Azure Arc (includingmachines. This includes VMs in AWS and GCP compute).GCP.

The extension actsserves as a management and deployment interface, which orchestrates andinterface. It wraps the Defender for Endpoint installationinstall scripts inside the operating system and reflectsreports its provisioning statestatus to the Azure management plane. The installation process recognizes an existingIf Defender for Endpoint installationis already installed, the process detects it and connects it to Defender for Cloud by automatically adding Defender for Endpoint service tags.

In case you haveSome devices runningmight run Windows Server 2012 R2 or Windows Server 2016, and those devices are provisioned2016 with the legacy, Log Analytics-based Defender for Endpoint solution,solution. For these devices, Defender for Cloud's deployment process deploys the Defender for Endpoint unified solution. After successful deployment, itIt then stops and disables the legacy Defender for Endpoint process (MsSense.exe) on thesethose machines.

See also

For more details, see these related articles: