Onboard servers through Microsoft Defender for Endpoint's onboarding experience
In brief
The documentation recommends onboarding servers through Defender for Servers Plan 2, notes automatic Defender for Endpoint extension onboarding for supported Azure and Azure Arc machines, and identifies standalone server licenses as alternatives.
What Defender admins need to know
Administrators can use this guidance when choosing a server onboarding and licensing approach; no action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Onboard servers through Microsoft Defender for Endpoint's onboarding experience
- Microsoft Defender for Endpoint for servers
- Microsoft Defender for Business servers (for small and medium-sized businesses only)
Integration with Microsoft Defender for Servers
Defender for Endpoint integrates seamlessly with Defender for Servers (in Defender for Cloud). If your subscription includes Defender for Servers Plan 1 or Plan 2, you can:
@@ -11,11 +11,13 @@ ms.collection: - tier2 ms.topic: install-set-up-deploy ms.subservice: onboard-ms.date: 11/17/2025+ms.date: 09/03/2026+ms.custom: msecd-doc-authoring-1015+ai-usage: ai-assisted appliesto: - Microsoft Defender for Endpoint Plan 1 - Microsoft Defender for Endpoint Plan 2-+#customer intent: As a security administrator, I want to onboard Windows and Linux servers to Defender for Endpoint so that I can protect and monitor them. --- # Onboard servers through Microsoft Defender for Endpoint's onboarding experience@@ -39,6 +41,21 @@ To onboard servers to Defender for Endpoint, [server licenses](/office365/servic - Microsoft Defender for Endpoint for servers - [Microsoft Defender for Business servers](/defender-business/get-defender-business#how-to-get-microsoft-defender-for-business-servers) (for small and medium-sized businesses only) +> [!TIP]+> For most organizations, Microsoft recommends onboarding servers through **Microsoft Defender for Servers Plan 2** as part of [Microsoft Defender for Cloud](/azure/defender-for-cloud/defender-for-servers-overview). Plan 2 includes Defender for Endpoint server protection and capabilities specific to server workloads:+>+> - Agentless machine scanning for vulnerabilities, malware, and secrets+> - File integrity monitoring+> - Just-in-time virtual machine access+> - Regulatory compliance assessment+> - Premium Microsoft Defender Vulnerability Management capabilities+> - Operating system configuration assessment based on the Microsoft Cloud Security Benchmark+> - A 500-MB daily data ingestion benefit for each protected machine+>+> Defender for Cloud automatically onboards the Defender for Endpoint extension to supported Azure virtual machines and Azure Arc-enabled machines, so you don't need per-machine onboarding scripts. For a feature comparison, see [Defender for Servers plan features](/azure/defender-for-cloud/defender-for-servers-overview#plan-protection-features).+>+> If your organization doesn't use Defender for Cloud, the standalone Microsoft Defender for Endpoint for servers and Microsoft Defender for Business servers licenses are alternatives.+ ## Integration with Microsoft Defender for Servers Defender for Endpoint integrates seamlessly with [Defender for Servers](/azure/defender-for-cloud/defender-for-servers-overview) (in Defender for Cloud). If your subscription includes Defender for Servers Plan 1 or Plan 2, you can: 