Vulnerability scanning in the Defender for Servers plan in Microsoft Defender for Cloud.
In brief
The article updates its date and authoring metadata, clarifies the Cloud overview and Vulnerabilities > Cloud navigation, improves software inventory and AWS/GCP onboarding links, and labels the BYOL scanning workflow more specifically.
What Defender admins need to know
Administrators get clearer navigation and links when reviewing vulnerability insights and BYOL scanning guidance; no action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
::: zone pivot="defender-portal"
Vulnerability scanning options in Defender for Servers
Microsoft Defender Vulnerability Management is now under Exposure Management and supports both cloud and device environments. Access vulnerability scanning in the Microsoft Defender portal at Exposure Management > Vulnerability Management > Overview > Cloud.
This centralized experienceThe Cloud overview page provides comprehensive vulnerability insights across your cloud infrastructure, including:
- Cloud vulnerabilities overview: Key metrics and trends for cloud-specific vulnerabilities
- Top cloud common vulnerabilities and exposures (CVEs): Most critical vulnerabilities affecting your cloud resources
The Defender for Servers plan in Microsoft Defender for Cloud provides vulnerability scanning for connected machines. You can access this data from the unified Vulnerability Management dashboard under Exposure Management.
For detailed analysis, go to Exposure Management > Vulnerability Management > Vulnerabilities > Cloud. This viewThe Vulnerabilities > Cloud page shows cloud vulnerabilities with enhanced filtering and risk-based prioritization alongside device vulnerabilities.
Key benefits of the integrated Exposure Management approach:
- Scanning consistency: Use a consistent vulnerability scanner across a range of use cases, in multicloud environments, and different host runtimes.
- Risk reduction: Discover vulnerabilities and misconfigurations in near real time.
- Prioritization: Prioritize vulnerabilities based on the threat landscape and detections in your organization.
- Software inventory:
Get information about yourReview your software inventory in Defender for Cloud. - Premium features: Use Defender Vulnerability Management premium features in Defender for Servers Plan 2, including certificate assessment, baseline assessment, vulnerable application blocking, and more.
Vulnerability scanning with Defender Vulnerability Management is supported for Azure virtual machines (VMs), onboarded AWS machines, and onboarded GCP machines that are connected to Defender for Cloud. It's also supported for on-premises VMs that are onboard on-premises machines as Azure Arc VMs.
For a quick overview of Defender Vulnerability Management, watch this video:
Instead of integrated Defender Vulnerability Management scanning, you can use your own bring your own license (BYOL) vulnerability scanner. Qualys and Rapid7 scanners are supported.
Here's how itBYOL vulnerability scanning works:
- Supported solutions report vulnerability data to the partner's management platform.
- Solution platforms provide vulnerability and health monitoring data back to Defender for Cloud.
--- | ---
No solution | If you don't have an agent-based vulnerability scanning solution enabled on VMs, Defender for Cloud automatically runs agentless scanning with Defender Vulnerability Management.
Defender Vulnerability Management integration | If machines run the Defender for Endpoint agent, Defender for Cloud shows a unified vulnerability assessment view with optimized coverage and data freshness.
- Machines using only one method, agent-based scanning or agentless scanning, show results from that method.
- Machines using both methods show agent-based results only for better freshness. BYOL solution | If you're using a partner vulnerability assessment solution, Defender for Cloud shows partner results by default. Defender for Cloud shows agentless results for machines that don't have the partner agent installed, or for machines that aren't reporting findings correctly.
You can change this behavior and always show results from Defender Vulnerability Management. To do this, manually enable vulnerability scanning on a subscription Vulnerability assessment for machines on the Environment settings page in Defender for Cloud.
Premium vulnerability management features
@@ -2,8 +2,9 @@ title: Vulnerability scanning in the Defender for Servers plan in Microsoft Defender for Cloud. description: Learn about vulnerability scanning in the Defender for Servers plan in Microsoft Defender for Cloud. ms.topic: how-to-ms.date: 05/27/2026+ms.date: 07/03/2026 zone_pivot_groups: defender-portal-experience+ms.custom: msecd-doc-authoring-1013 #customer intent: As a user, I want to configure vulnerability scanning for servers so I can prioritize and remediate security risks across my environments. ai-usage: ai-assisted ---@@ -12,9 +13,11 @@ ai-usage: ai-assisted ::: zone pivot="defender-portal" +## Vulnerability scanning options in Defender for Servers+ Microsoft Defender Vulnerability Management is now under **Exposure Management** and supports both cloud and device environments. Access vulnerability scanning in the Microsoft Defender portal at **Exposure Management** > **Vulnerability Management** > **Overview** > **Cloud**. -This centralized experience provides comprehensive vulnerability insights across your cloud infrastructure, including:+The Cloud overview page provides comprehensive vulnerability insights across your cloud infrastructure, including: - **Cloud vulnerabilities overview**: Key metrics and trends for cloud-specific vulnerabilities - **Top cloud common vulnerabilities and exposures (CVEs)**: Most critical vulnerabilities affecting your cloud resources@@ -24,7 +27,7 @@ This centralized experience provides comprehensive vulnerability insights across The Defender for Servers plan in Microsoft Defender for Cloud provides vulnerability scanning for connected machines. You can access this data from the unified Vulnerability Management dashboard under Exposure Management. -For detailed analysis, go to **Exposure Management** > **Vulnerability Management** > **Vulnerabilities** > **Cloud**. This view shows cloud vulnerabilities with enhanced filtering and risk-based prioritization alongside device vulnerabilities.+For detailed analysis, go to **Exposure Management** > **Vulnerability Management** > **Vulnerabilities** > **Cloud**. The **Vulnerabilities** > **Cloud** page shows cloud vulnerabilities with enhanced filtering and risk-based prioritization alongside device vulnerabilities. Key benefits of the integrated Exposure Management approach: @@ -54,10 +57,10 @@ Integrated vulnerability assessment provides many benefits: - **Scanning consistency**: Use a consistent vulnerability scanner across a range of use cases, in multicloud environments, and different host runtimes. - **Risk reduction**: Discover vulnerabilities and misconfigurations in near real time. - **Prioritization**: Prioritize vulnerabilities based on the threat landscape and detections in your organization.-- **Software inventory**: Get information about your [software inventory](asset-inventory.md#review-software-inventory).+- **Software inventory**: [Review your software inventory in Defender for Cloud](asset-inventory.md#review-software-inventory). - **Premium features**: Use Defender Vulnerability Management premium features in Defender for Servers Plan 2, including certificate assessment, baseline assessment, vulnerable application blocking, and more. -Vulnerability scanning with Defender Vulnerability Management is supported for Azure virtual machines (VMs), [AWS machines](quickstart-onboard-aws.md), and [GCP machines](quickstart-onboard-gcp.md) that are connected to Defender for Cloud. It's also supported for on-premises VMs that are [onboarded as Azure Arc VMs](quickstart-onboard-machines.md).+Vulnerability scanning with Defender Vulnerability Management is supported for Azure virtual machines (VMs), [onboarded AWS machines](quickstart-onboard-aws.md), and [onboarded GCP machines](quickstart-onboard-gcp.md) that are connected to Defender for Cloud. It's also supported for on-premises VMs that are [onboard on-premises machines as Azure Arc VMs](quickstart-onboard-machines.md). For a quick overview of Defender Vulnerability Management, watch this video: @@ -74,7 +77,7 @@ Vulnerability scanning with integrated Defender Vulnerability Management takes a Instead of integrated Defender Vulnerability Management scanning, you can use your own bring your own license (BYOL) vulnerability scanner. Qualys and Rapid7 scanners are supported. -Here's how it works:+Here's how BYOL vulnerability scanning works: - Supported solutions report vulnerability data to the partner's management platform. - Solution platforms provide vulnerability and health monitoring data back to Defender for Cloud.@@ -94,7 +97,7 @@ Agentless scanning extends the visibility of Defender for Cloud to reach more de --- | --- **No solution** | If you don't have an agent-based vulnerability scanning solution enabled on VMs, Defender for Cloud automatically runs agentless scanning with Defender Vulnerability Management. **Defender Vulnerability Management integration** | If machines run the Defender for Endpoint agent, Defender for Cloud shows a unified vulnerability assessment view with optimized coverage and data freshness.<br/><br/>- Machines using only one method, agent-based scanning or agentless scanning, show results from that method.<br/>- Machines using both methods show agent-based results only for better freshness.-**BYOL solution** | If you're using a [partner vulnerability assessment solution](deploy-vulnerability-assessment-byol-vm.md), Defender for Cloud shows partner results by default. Defender for Cloud shows agentless results for machines that don't have the partner agent installed, or for machines that aren't reporting findings correctly.<br/><br/>You can change this behavior and always show results from Defender Vulnerability Management. To do this, [manually enable](deploy-vulnerability-assessment-defender-vulnerability-management.md#enable-vulnerability-scanning-on-a-subscription) **Vulnerability assessment for machines** on the **Environment settings** page in Defender for Cloud.+**BYOL solution** | If you're using a [partner vulnerability assessment solution](deploy-vulnerability-assessment-byol-vm.md), Defender for Cloud shows partner results by default. Defender for Cloud shows agentless results for machines that don't have the partner agent installed, or for machines that aren't reporting findings correctly.<br/><br/>You can change this behavior and always show results from Defender Vulnerability Management. To do this, [manually enable vulnerability scanning on a subscription](deploy-vulnerability-assessment-defender-vulnerability-management.md#enable-vulnerability-scanning-on-a-subscription) **Vulnerability assessment for machines** on the **Environment settings** page in Defender for Cloud. ## Premium vulnerability management features 