Migrate servers from Microsoft Defender for Endpoint to Microsoft Defender for Servers
In brief
The article now links to prerequisites and machine-type migration steps, clarifies Defender for Endpoint integration opt-ins, and updates Azure Arc and multicloud connector guidance.
What Defender admins need to know
Administrators planning server migrations have clearer guidance for validating prerequisites and configuring required integrations.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
ms.collection:
- m365-security
- tier2
ms.custom: migrationguides, msecd-doc-authoring-
10141016 ms.date:06/16/07/03/2026 appliesto:- Microsoft Defender for Endpoint Plan 1
- Microsoft Defender for Endpoint Plan 2
Migrate servers from Microsoft Defender for Endpoint to Microsoft Defender for Servers
This article describes how to migrate your servers from Defender for Endpoint to Defender for Servers. Before you begin, review the prerequisites and migration steps for your server type.
Defender for Endpoint is an enterprise endpoint security platform designed to helpplatform. It helps organizations prevent, detect, investigate, and respond to advanced threats. TheWith a Defender for Endpoint for servers license enableslicense, you tocan onboard a server to Defender for Endpoint.
Defender for Servers is part of the Microsoft Defender for Cloud offering, a solution. Defender for Cloud provides cloud security posture management (CSPM) and cloud workload protection (CWP) that. It finds weak spots acrossin your cloud configuration. Defender for Cloud alsosetup and helps strengthen the overall security posture of your environment, and can protect workloads across multicloud and hybrid environments from evolving threats.environments.
While both Defender for Endpoint for servers and Defender for ServersBoth products offer server protection capabilities,protection, but Defender for Servers is our primary solution to protect servers.
How do I migrate my servers from Defender for Endpoint to Defender for Cloud?
If you have servers onboarded to Defender for Endpoint, the migration process varies dependingsteps depend on the machine type, but there'stype. However, all machines share a set of shared prerequisites. Defender for Cloud is a subscription-based service in the Microsoft Azure portal. Therefore,You must enable Defender for Cloud and underlying plans likea Defender for Servers Planplan (Plan 1 or Plan 2 need to be enabled2) on your Azure subscriptions.
Before you enable Defender for Cloud
Enable a Defender for Servers plan on your subscription. In case you're using Defender for Servers Plan 2, make sure to also enable it on the Log Analytics workspace your machines are connected to. Enabling Defender for Servers Plan 2 on the Log Analytics workspace lets you use optional features, like File Integrity Monitoring.
Make sure the Defender for Endpoint integration is enabled on your subscription. If you have preexisting Azure subscriptions, you might see one or both
of the twoopt-in buttons for Allow MDE access to EWACS data and Allow MDE Unified Agent for EWACS as shown in the following image::::image type="content" source="media/mde-integration.png" alt-text="Screenshot that shows how to enable Defender for Endpoint integration." lightbox="media/mde-integration.png":::
If you
havesee either of these opt-in buttons in your environment, make sure to enable integration for both. On new subscriptions, both options are enabled by default, andyouthe buttons don'tsee these buttons in your environment.appear.If you
're planningplan to use Azure Arc,make surecheck that the connectivity requirements are met. Defender for Cloud requires all on-premises and non-Azure machines tobe connected usingconnect through the Azure Arc agent.In addition,Azure Arc doesn't supportallevery operating system that Defender for Endpointsupported operating systems.supports. Forhelp with yourplanningprocess,help, see Azure Arc deployments.(Recommended) If you want to see vulnerability findings in Defender for Cloud, make sure to enable vulnerability assessment in Defender for Cloud.
If you're using Amazon Web Services (AWS) or Google Cloud Platform (GCP), follow these steps to migrate those VMs:
Create a
newmulticloud connector on your subscription.For more information about this connector,To learn more, see AWS accounts or GCP projects.On
your multicloudthe connector,enableturn on Defender for Serversonfor AWS connectors or GCP connectors.EnableTurn on autoprovisioning on themulticloudconnector for the Azure Arc agent, the Defender for Endpoint extension, and Vulnerability Assessment.ForIf you use Defender for Servers Plan 2,enablealso turn on agentless machine scanning.:::image type="content" source="media/select-plans-aws-gcp.png" alt-text="Screenshot that shows how to enable autoprovisioning for Azure Arc agent." lightbox="media/select-plans-aws-gcp.png":::
ForTo learn more information,about multicloud support and onboarding non-Azure machines, see the following resources:Defender for Cloud's multicloud capabilities and Connect your non-Azure machines to Microsoft Defender for Cloud.
Defender for Cloud's multicloud capabilitiesConnect your non-Azure machines to Microsoft Defender for Cloud
What happens once all migration steps are completed?
After you complete the relevant migration steps, Defender for Cloud deploys the Defender for Endpoint extension for Windows (MDE.Windows) or Linux (MDE.Linux) to your Azure VMs and Arc-connected non-Azure machines connected through Azure Arc (includingmachines. This includes VMs in AWS and GCP compute).GCP.
The extension actsserves as a management and deployment interface, which orchestrates andinterface. It wraps the Defender for Endpoint installationinstall scripts inside the operating system and reflectsreports its provisioning statestatus to the Azure management plane. The installation process recognizes an existingIf Defender for Endpoint installationis already installed, the process detects it and connects it to Defender for Cloud by automatically adding Defender for Endpoint service tags.
In case you haveSome devices runningmight run Windows Server 2012 R2 or Windows Server 2016, and those devices are provisioned2016 with the legacy, Log Analytics-based Defender for Endpoint solution,solution. For these devices, Defender for Cloud's deployment process deploys the Defender for Endpoint unified solution. After successful deployment, itIt then stops and disables the legacy Defender for Endpoint process (MsSense.exe) on thesethose machines.
See also
For more details, see these related articles:
@@ -10,8 +10,8 @@ ms.localizationpriority: medium ms.collection: - m365-security - tier2-ms.custom: migrationguides, msecd-doc-authoring-1014-ms.date: 06/16/2026+ms.custom: migrationguides, msecd-doc-authoring-1016+ms.date: 07/03/2026 appliesto: - Microsoft Defender for Endpoint Plan 1 - Microsoft Defender for Endpoint Plan 2@@ -20,17 +20,17 @@ ai-usage: ai-assisted # Migrate servers from Microsoft Defender for Endpoint to Microsoft Defender for Servers -This article describes how to migrate your servers from Defender for Endpoint to Defender for Servers.+This article describes how to migrate your servers from Defender for Endpoint to Defender for Servers. Before you begin, review the [prerequisites](#before-you-enable-defender-for-cloud) and migration steps for your server type. -[Defender for Endpoint](microsoft-defender-endpoint.md) is an enterprise endpoint security platform designed to help organizations prevent, detect, investigate, and respond to advanced threats. The Defender for Endpoint for servers license enables you to onboard a server to Defender for Endpoint.+[Defender for Endpoint](microsoft-defender-endpoint.md) is an endpoint security platform. It helps organizations prevent, detect, and respond to advanced threats. With a Defender for Endpoint for servers license, you can onboard a server to Defender for Endpoint. -[Defender for Servers](/azure/defender-for-cloud/defender-for-servers-overview) is part of the [Microsoft Defender for Cloud](/azure/defender-for-cloud/defender-for-cloud-introduction) offering, a solution for cloud security posture management (CSPM) and cloud workload protection (CWP) that finds weak spots across your cloud configuration. Defender for Cloud also helps strengthen the overall security posture of your environment, and can protect workloads across multicloud and hybrid environments from evolving threats.+[Defender for Servers](/azure/defender-for-cloud/defender-for-servers-overview) is part of [Microsoft Defender for Cloud](/azure/defender-for-cloud/defender-for-cloud-introduction). Defender for Cloud provides cloud security posture management (CSPM) and cloud workload protection (CWP). It finds weak spots in your cloud setup and helps protect workloads across multicloud and hybrid environments. -While both Defender for Endpoint for servers and Defender for Servers offer server protection capabilities, Defender for Servers is our primary solution to protect servers.+Both products offer server protection, but Defender for Servers is our primary solution to protect servers. ## How do I migrate my servers from Defender for Endpoint to Defender for Cloud? -If you have servers onboarded to Defender for Endpoint, the migration process varies depending on machine type, but there's a set of shared prerequisites. Defender for Cloud is a subscription-based service in the [Microsoft Azure portal](https://portal.azure.com). Therefore, Defender for Cloud and underlying plans like Defender for Servers Plan 1 or Plan 2 need to be enabled on Azure subscriptions.+If you have servers onboarded to Defender for Endpoint, the migration steps depend on the machine type. However, all machines share a set of prerequisites. Defender for Cloud is a subscription-based service in the [Microsoft Azure portal](https://portal.azure.com). You must enable Defender for Cloud and a Defender for Servers plan (Plan 1 or Plan 2) on your Azure subscriptions. ### Before you enable Defender for Cloud @@ -52,13 +52,13 @@ To enable Defender for Servers for Azure VMs and non-Azure servers connected thr 1. [Enable a Defender for Servers plan on your subscription](/azure/defender-for-cloud/enable-enhanced-security). In case you're using Defender for Servers Plan 2, make sure to also enable it on the Log Analytics workspace your machines are connected to. Enabling Defender for Servers Plan 2 on the Log Analytics workspace lets you use optional features, like [File Integrity Monitoring](/azure/defender-for-cloud/file-integrity-monitoring-overview). -1. Make sure the [Defender for Endpoint integration](/azure/defender-for-cloud/integration-defender-for-endpoint) is enabled on your subscription. If you have preexisting Azure subscriptions, you might see one or both of the two opt-in buttons shown in the following image:+1. Make sure the [Defender for Endpoint integration](/azure/defender-for-cloud/integration-defender-for-endpoint) is enabled on your subscription. If you have preexisting Azure subscriptions, you might see one or both opt-in buttons for **Allow MDE access to EWACS data** and **Allow MDE Unified Agent for EWACS** as shown in the following image: :::image type="content" source="media/mde-integration.png" alt-text="Screenshot that shows how to enable Defender for Endpoint integration." lightbox="media/mde-integration.png"::: - If you have either of these buttons in your environment, make sure to enable integration for both. On new subscriptions, both options are enabled by default, and you don't see these buttons in your environment.+ If you see either of these opt-in buttons in your environment, make sure to enable integration for both. On new subscriptions, both options are enabled by default, and the buttons don't appear. -1. If you're planning to use Azure Arc, make sure the connectivity requirements are met. Defender for Cloud requires all on-premises and non-Azure machines to be connected using the Azure Arc agent. In addition, Azure Arc doesn't support all Defender for Endpoint supported operating systems. For help with your planning process, see [Azure Arc deployments](/azure/azure-arc/servers/plan-at-scale-deployment).+1. If you plan to use Azure Arc, check that the connectivity requirements are met. Defender for Cloud requires all on-premises and non-Azure machines to connect through the Azure Arc agent. Azure Arc doesn't support every operating system that Defender for Endpoint supports. For planning help, see [Azure Arc deployments](/azure/azure-arc/servers/plan-at-scale-deployment). 1. (*Recommended*) If you want to see vulnerability findings in Defender for Cloud, make sure to enable [vulnerability assessment](/azure/defender-for-cloud/monitoring-components?tabs=autoprovision-va#vulnerability-assessment) in Defender for Cloud. @@ -81,29 +81,28 @@ For on-premises machines, you have several onboarding options: If you're using Amazon Web Services (AWS) or Google Cloud Platform (GCP), follow these steps to migrate those VMs: -1. Create a new multicloud connector on your subscription. For more information about this connector, see [AWS accounts](/azure/defender-for-cloud/quickstart-onboard-aws?pivots=env-settings) or [GCP projects](/azure/defender-for-cloud/quickstart-onboard-gcp?pivots=env-settings).+1. Create a multicloud connector on your subscription. To learn more, see [AWS accounts](/azure/defender-for-cloud/quickstart-onboard-aws?pivots=env-settings) or [GCP projects](/azure/defender-for-cloud/quickstart-onboard-gcp?pivots=env-settings). -1. On your multicloud connector, enable Defender for Servers on [AWS connectors](/azure/defender-for-cloud/quickstart-onboard-aws?pivots=env-settings#prerequisites) or [GCP connectors](/azure/defender-for-cloud/quickstart-onboard-gcp?pivots=env-settings#configure-the-servers-plan).+1. On the connector, turn on Defender for Servers for [AWS connectors](/azure/defender-for-cloud/quickstart-onboard-aws?pivots=env-settings#prerequisites) or [GCP connectors](/azure/defender-for-cloud/quickstart-onboard-gcp?pivots=env-settings#configure-the-servers-plan). -1. Enable autoprovisioning on the multicloud connector for the Azure Arc agent, Defender for Endpoint extension, and Vulnerability Assessment. For Defender for Servers Plan 2, enable agentless machine scanning.+1. Turn on autoprovisioning on the connector for the Azure Arc agent, the Defender for Endpoint extension, and Vulnerability Assessment. If you use Defender for Servers Plan 2, also turn on agentless machine scanning. :::image type="content" source="media/select-plans-aws-gcp.png" alt-text="Screenshot that shows how to enable autoprovisioning for Azure Arc agent." lightbox="media/select-plans-aws-gcp.png"::: -For more information, see the following resources:--- [Defender for Cloud's multicloud capabilities](https://aka.ms/mdcmc)-- [Connect your non-Azure machines to Microsoft Defender for Cloud](/azure/defender-for-cloud/quickstart-onboard-machines)+To learn more about multicloud support and onboarding non-Azure machines, see [Defender for Cloud's multicloud capabilities](https://aka.ms/mdcmc) and [Connect your non-Azure machines to Microsoft Defender for Cloud](/azure/defender-for-cloud/quickstart-onboard-machines). ## What happens once all migration steps are completed? -After you complete the relevant migration steps, Defender for Cloud deploys the Defender for Endpoint extension (`MDE.Windows` or `MDE.Linux`) to your Azure VMs and non-Azure machines connected through Azure Arc (including VMs in AWS and GCP compute).+After you complete the migration steps, Defender for Cloud deploys the Defender for Endpoint extension for Windows (`MDE.Windows`) or Linux (`MDE.Linux`) to your Azure VMs and Arc-connected non-Azure machines. This includes VMs in AWS and GCP. -The extension acts as a management and deployment interface, which orchestrates and wraps the Defender for Endpoint installation scripts inside the operating system and reflects its provisioning state to the Azure management plane. The installation process recognizes an existing Defender for Endpoint installation and connects it to Defender for Cloud by automatically adding Defender for Endpoint service tags.+The extension serves as a management interface. It wraps the Defender for Endpoint install scripts inside the operating system and reports its status to the Azure management plane. If Defender for Endpoint is already installed, the process detects it and connects it to Defender for Cloud by adding Defender for Endpoint service tags. -In case you have devices running Windows Server 2012 R2 or Windows Server 2016, and those devices are provisioned with the legacy, Log Analytics-based Defender for Endpoint solution, Defender for Cloud's deployment process deploys the Defender for Endpoint [unified solution](onboard-server.md#functionality-in-the-modern-unified-solution-for-windows-server-2016-and-windows-server-2012-r2). After successful deployment, it stops and disables the legacy Defender for Endpoint process (`MsSense.exe`) on these machines.+Some devices might run Windows Server 2012 R2 or Windows Server 2016 with the legacy, Log Analytics-based Defender for Endpoint solution. For these devices, Defender for Cloud deploys the Defender for Endpoint [unified solution](onboard-server.md#functionality-in-the-modern-unified-solution-for-windows-server-2016-and-windows-server-2012-r2). It then stops and disables the legacy process (`MsSense.exe`) on those machines. ## See also +For more details, see these related articles:+ - [Defender for Cloud: Enable Defender for Endpoint integration](/azure/defender-for-cloud/enable-defender-for-endpoint) - [Defender for Cloud: Agentless machine scanning](/azure/defender-for-cloud/concept-agentless-data-collection) - [Defender for Cloud: Remediate Defender for Endpoint misconfigurations (agentless)](/azure/defender-for-cloud/endpoint-detection-misconfiguration) 