We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Defender for Servers
Microsoft Defender for Servers, UAE

Half of what Plan 2 does needs your servers onboarded to Azure Arc. Buy the plan without the Arc work and you paid for features you cannot use.

Plan 1 is endpoint detection and response for servers, anywhere. Plan 2 adds agentless vulnerability, malware and secrets scanning, file integrity monitoring, just-in-time access and baseline assessment. Several of those are documented as applicable only to machines onboarded through Azure Arc, which makes Arc the real prerequisite rather than an implementation detail.

Book a server protection reviewSee what each plan includes
Microsoft Defender for Servers for UAE organisations
  • Two plansPlan 1 EDR, Plan 2 adds twelve capabilities
  • Azure, AWS, GCPPlus on-premises Windows and Linux
  • AgentlessMost Plan 2 scanning needs no agent
  • 30 day trialCannot be stopped, paused or extended
What it does

Seven things that decide which plan you need and what it will actually deliver.

Microsoft describes Defender for Servers as reducing security risk and exposure for machines, providing recommendations to improve and remediate posture, and protecting machines against real-time threats and attacks. The plan you need follows from what your estate looks like and how it is connected, not from a feature list read in isolation.

Windows and Linux, across three clouds and on-premises

Microsoft states it protects Windows and Linux machines in multicloud environments spanning Azure, Amazon Web Services and Google Cloud Platform, and on-premises. For UAE groups whose estate accumulated across an Azure migration, an acquisition running on AWS and a data centre nobody has decommissioned, that single coverage statement is usually the reason it gets evaluated.

Plan 1 is endpoint detection and response, delivered automatically

Plan 1 focuses on the endpoint detection and response capability provided by the Defender for Endpoint integration, with automatic onboarding, integrated alerts and incidents, software inventory discovery, regulatory compliance assessment and agent-based vulnerability scanning. For an organisation whose servers currently run traditional antivirus, that is already a substantial change.

Plan 2 is mostly agentless, which changed the deployment story

Agentless vulnerability scanning, agentless malware scanning and agentless machine secrets scanning are all Plan 2 capabilities. Microsoft also notes that Defender for Servers no longer uses the Log Analytics agent or Azure Monitor Agent for most plan features, with agentless scanning and the Defender for Endpoint integration replacing them, which removes most of the historic agent burden.

Just-in-time access, file integrity monitoring and baselines

Plan 2 adds just-in-time virtual machine access on Azure and AWS, file integrity monitoring, and assessment of operating system configuration against the compute security baselines in the Microsoft Cloud Security Benchmark. Those three together are what turn the product from threat detection into posture management, and they are the ones most often cited in an audit finding.

Azure Arc is a dependency, not a nice to have

The published feature table is explicit. Operating system system updates and baseline misconfiguration assessment are applicable only to machines onboarded with Azure Arc. File integrity monitoring is applicable to AWS and GCP machines only when onboarded with Arc. And for on-premises, Microsoft states that with direct onboarding you will not have full access to Plan 2 features.

Defender Experts for Servers, if you have no analysts

A managed extended detection and response service for server workloads, where Microsoft analysts triage, investigate and contain incidents then hand off with guided steps. It covers all Plan 1 and Plan 2 alerts where the detection source is Defender for Servers, across Windows and Linux on Azure, AWS, GCP and on-premises. It is sold separately, and DNS alerts are not in scope.

A thirty day trial that cannot be paused

Microsoft states that enabling a plan starts a 30-day trial period which you cannot stop, pause or extend, and advises planning ahead to meet your evaluation goals. That is worth reading before somebody enables it during a quiet week to have a look. An evaluation that begins two weeks before a holiday period effectively has half the time it appears to.

The prerequisite that decides the project

Plan 2 without Azure Arc is a partial deployment, and the gaps are documented.

The Arc dependency is stated in the published feature table rather than hidden, and it is the single most common reason a Defender for Servers deployment underdelivers.

  • Operating system system updates, and operating system baseline misconfiguration assessment against the Microsoft Cloud Security Benchmark, are both listed as only applicable to machines onboarded with Azure Arc.
  • File integrity monitoring is listed as available on Azure, AWS and GCP, but only applicable to AWS and GCP machines onboarded with Azure Arc.
  • For on-premises machines, Microsoft recommends onboarding as Azure Arc virtual machines and states that with direct onboarding to Defender for Cloud you will not have full access to Plan 2 features.
  • So the sequencing that works is Arc first, plan second. Organisations that buy the plan and schedule the Arc work afterwards spend the first quarter explaining why the capabilities in the business case are not visible yet.
Ask us to scope the Arc work first
How we approach it

Four things that stop a server protection project delivering half of what was bought.

This is a product where the licensing decision and the infrastructure decision are the same decision, and where the trial clock starts whether or not you were ready for it.

We scope the Azure Arc work before the plan decision

Operating system updates and baseline misconfiguration assessment only apply to Arc-onboarded machines. File integrity monitoring on AWS and GCP only applies to Arc-onboarded machines. On-premises direct onboarding does not give full Plan 2 access. Arc is therefore the first line item in the plan, not a task somebody picks up in phase three.

We split the estate rather than buying one plan for everything

Microsoft allows Plan 1 to be enabled and disabled at the resource level per server, while Plan 2 cannot be enabled per resource but can be disabled per resource. That asymmetry is a design tool. A subscription on Plan 2 with specific resources disabled behaves very differently commercially from a blanket decision, and it is worth modelling.

We act on the secrets scanning findings, because nobody expects them

Agentless machine secrets scanning is a Plan 2 capability and it consistently produces the most uncomfortable output of any first run. Credentials in scripts, keys in configuration files, and connection strings on servers nobody has logged into for years. Those findings need an owner and a rotation plan before the report is circulated.

We time the thirty day trial around an actual evaluation

Microsoft is explicit that the trial cannot be stopped, paused or extended, and advises planning ahead to meet your evaluation goals. We agree what will be tested, who will look at it, and what decision the evaluation is meant to support, before anybody enables the plan. Otherwise the trial expires having proved nothing.

Where this fits

Six UAE situations where server protection needs modernising.

The common thread is that endpoint security moved on and servers did not, usually because server changes carry more risk and nobody wanted to own the outage.

A group with servers spread across three clouds and a data centre

Defender for Servers protects Windows and Linux across Azure, AWS, GCP and on-premises. The practical route Microsoft recommends is onboarding AWS and GCP machines as Azure Arc virtual machines to get full feature access, and connecting AWS accounts and GCP projects to Defender for Cloud, which can enable the plan as part of the connection process.

A regulated firm with a file integrity monitoring requirement

File integrity monitoring is a Plan 2 capability and needs a Log Analytics workspace, either existing or created during configuration. On AWS and GCP it applies only to machines onboarded with Azure Arc. Where an obligation names file integrity monitoring specifically, that combination of dependencies is the actual project rather than the licence purchase.

An organisation that has never scanned its servers for secrets

Agentless machine secrets scanning, in Plan 2, finds credentials sitting on machines. In practice that means service account passwords in scripts, keys in configuration files and connection strings in places nobody remembers putting them. It is the finding that most often changes the priority of the wider secrets management conversation.

An operator that cannot deploy agents everywhere

The agent story changed. Microsoft states Defender for Servers no longer uses the Log Analytics agent or Azure Monitor Agent for most plan features, with agentless machine scanning and the Defender for Endpoint integration replacing them. For estates with change control that makes agent deployment slow, agentless scanning removes most of the obstacle.

An organisation with no server security analysts

Defender Experts for Servers is a managed extended detection and response service where Microsoft analysts triage, investigate and contain incidents then hand off with guided steps, and it includes proactive threat hunting and the ability to ask Microsoft experts about specific incidents. It is sold separately and requires Plan 1 or Plan 2 with Defender for Endpoint deployed.

A business trying to close down standing management access

Just-in-time virtual machine access, a Plan 2 capability on Azure and AWS, closes management ports until access is requested and approved. For organisations that have been trying to remove permanently open remote desktop and secure shell access for years, it is a more achievable route than a network redesign.

Three positions

How UAE organisations protect servers today.

The middle column is very common. Endpoint protection was modernised for laptops during a Microsoft 365 project, and the servers kept whatever they had because nobody wanted to touch them.
Endpoint detection and response on servers
Defender for Servers Plan 2 with ArcYes
Traditional antivirus on serversNo
Inconsistent or unknownNo
Vulnerability scanning without an agent
Defender for Servers Plan 2 with ArcYes
Traditional antivirus on serversNo
Inconsistent or unknownNo
Secrets found on machines
Defender for Servers Plan 2 with ArcYes
Traditional antivirus on serversNo
Inconsistent or unknownNo
Operating system baselines assessed
Defender for Servers Plan 2 with ArcYes, with Arc
Traditional antivirus on serversNo
Inconsistent or unknownNo
File integrity monitoring
Defender for Servers Plan 2 with ArcYes
Traditional antivirus on serversSometimes
Inconsistent or unknownNo
Just-in-time management access
Defender for Servers Plan 2 with ArcYes
Traditional antivirus on serversNo
Inconsistent or unknownNo
Covers AWS and GCP machines too
Defender for Servers Plan 2 with ArcYes
Traditional antivirus on serversSeparately
Inconsistent or unknownNo
Alerts correlate with the rest of the estate
Defender for Servers Plan 2 with ArcYes
Traditional antivirus on serversNo
Inconsistent or unknownNo
Regulatory compliance assessed continuously
Defender for Servers Plan 2 with ArcYes
Traditional antivirus on serversNo
Inconsistent or unknownNo
Answer to what is running on that server
Defender for Servers Plan 2 with ArcInventory
Traditional antivirus on serversGuess
Inconsistent or unknownNone
Feature
Defender for Servers Plan 2 with Arc
Traditional antivirus on servers
Inconsistent or unknown
Endpoint detection and response on servers
YesNoNo
Vulnerability scanning without an agent
YesNoNo
Secrets found on machines
YesNoNo
Operating system baselines assessed
Yes, with ArcNoNo
File integrity monitoring
YesSometimesNo
Just-in-time management access
YesNoNo
Covers AWS and GCP machines too
YesSeparatelyNo
Alerts correlate with the rest of the estate
YesNoNo
Regulatory compliance assessed continuously
YesNoNo
Answer to what is running on that server
InventoryGuessNone
Plan 1 against Plan 2

Nineteen capabilities, and where each one applies.

Reproduced from the published plan feature table. The availability column carries the conditions that determine whether a capability is actually usable in your estate.
CapabilityPlan 1Plan 2Where it applies
Multicloud and hybrid supportYesYesAzure, AWS, GCP and on-premises machines connected to Defender for Cloud
Defender for Endpoint automatic onboardingYesYesAll supported machines
Defender for Endpoint endpoint detection and responseYesYesAzure, AWS and GCP
Integrated alerts and incidentsYesYesAzure, AWS and GCP
Software inventory discoveryYesYesAzure, AWS and GCP
Regulatory compliance assessmentYesYesDifferent standards for different environments
Vulnerability scanning, agent basedYesYesAzure, AWS and GCP
Vulnerability scanning, agentlessNoYesAzure, AWS and GCP
Defender for DNS alertsNoYesAzure, AWS and GCP
Threat detection at the Azure network layerNoYesAzure
Operating system system updatesNoYesOnly machines onboarded with Azure Arc
Baseline misconfigurations, Microsoft Cloud Security BenchmarkNoYesOnly machines onboarded with Azure Arc
Defender Vulnerability Management premium featuresNoYesAvailable in the Defender portal only
Malware scanning, agentlessNoYesAzure, AWS and GCP
Machine secrets scanning, agentlessNoYesAzure, AWS and GCP
File integrity monitoringNoYesAWS and GCP machines only when onboarded with Azure Arc
Just-in-time virtual machine accessNoYesAzure and AWS
Network mapNoYesAzure
Free data ingestion, 500 MB per node per dayNoYesRequires a supported collection method such as Azure Monitor Agent
How an engagement runs

Five steps, and Arc comes before the plan.

Typically eight to sixteen weeks depending on how much Azure Arc onboarding is required. The Defender configuration itself is quick. Connecting the estate so the features actually apply is the work.
  1. 1

    Inventory the estate and its connection state

    How many Windows and Linux machines, in Azure, AWS, GCP and on-premises, and which of them are already Arc-enabled. Microsoft recommends onboarding AWS and GCP machines as Azure Arc virtual machines to take full advantage of the features, and notes that direct onboarding of on-premises machines limits Plan 2 access.

  2. 2

    Decide the plan against the capabilities you need

    Plan 1 for endpoint detection and response, which can be enabled and disabled per resource. Plan 2 for agentless vulnerability, malware and secrets scanning, file integrity monitoring, just-in-time access, network map and baseline assessment, enabled at subscription level with the option to disable specific resources.

  3. 3

    Do the Arc and prerequisite work first

    Azure Arc onboarding for the machines that need the Arc-dependent features. The Azure Policy machine configuration extension where operating system baseline assessment against the Microsoft Cloud Security Benchmark is required. A Log Analytics workspace where file integrity monitoring is in scope, and a supported collection method for the ingestion benefit.

  4. 4

    Enable deliberately, with the trial clock in mind

    The Defender for Endpoint extension installs automatically on supported machines, vulnerability management is enabled by default where that extension is present, and agentless scanning is enabled by default with Plan 2. The 30 day trial starts and cannot be paused, so the evaluation criteria and the people who will assess them are agreed beforehand.

  5. 5

    Work the findings and decide the operating model

    Secrets scanning results owned and rotated. Baseline misconfigurations prioritised. Just-in-time access configured for the machines with standing management ports. Then who works the alerts, whether Defender Experts for Servers fills that gap, and who owns remediation of posture recommendations on an ongoing basis.

Straight answers

What organisations ask about Defender for Servers.

Microsoft describes Plan 1 as entry-level, focused on the endpoint detection and response capabilities provided by the Defender for Endpoint integration, and Plan 2 as providing the same features plus others. In practice Plan 2 adds twelve further capabilities including agentless vulnerability, malware and secrets scanning, file integrity monitoring, just-in-time virtual machine access, network map, operating system baseline assessment and the free ingestion benefit.

Yes. Microsoft states it protects Windows and Linux machines in multicloud environments spanning Azure, Amazon Web Services and Google Cloud Platform, and on-premises. AWS accounts and GCP projects are connected to Defender for Cloud, and the plan can be enabled as part of that connection process. Onboarding those machines as Azure Arc virtual machines is what unlocks the full feature set.

Because several Plan 2 capabilities depend on it. Operating system system updates and baseline misconfiguration assessment are documented as only applicable to machines onboarded with Azure Arc. File integrity monitoring on AWS and GCP is only applicable to Arc-onboarded machines. And for on-premises, Microsoft states that with direct onboarding you will not have full access to Plan 2 features.

Much less than before. Microsoft states Defender for Servers no longer uses the Log Analytics agent or Azure Monitor Agent for most plan features, with agentless machine scanning and the Defender for Endpoint integration replacing them. Azure Monitor Agent remains a supported collection method for the 500 megabyte data ingestion benefit, so it has not disappeared entirely.

Partly, and the asymmetry matters. Microsoft states you can enable and disable Plan 1 at the resource level per server. Plan 2 cannot be enabled at the resource level, but it can be disabled at the resource level. So the pattern is to enable at subscription level and disable specific resources, rather than to enable machine by machine.

Four things, per the published guidance. A 30-day trial period begins which cannot be stopped, paused or extended. The Defender for Endpoint extension is automatically installed on all supported connected machines, and you can disable automatic provisioning if needed. Defender Vulnerability Management is enabled by default on machines with that extension. And with Plan 2, agentless scanning is enabled by default.

Free daily ingestion per node for eligible security data. Microsoft states you enable Defender for Servers Plan 2 on the Log Analytics workspace the machines report to, and that data must be collected through a supported method such as Azure Monitor Agent. There is one specific caveat worth noting: creating a data collection rule alone does not enable the benefit.

Credentials sitting on machines. In our experience the first run produces service account passwords embedded in scripts, keys in configuration files, and connection strings on servers that nobody has logged into for several years. It is a Plan 2 capability, it needs no agent, and the findings usually need a rotation plan attached before the report goes anywhere.

In Plan 2, and with two conditions. Microsoft states you set it up after enabling Plan 2 and that you need a Log Analytics workspace for it, either an existing one or one created during configuration. On AWS and GCP it is only applicable to machines onboarded with Azure Arc. Where a compliance obligation names file integrity monitoring, both conditions belong in the project plan.

Plan 2 assesses operating system configuration settings against the compute security baselines in the Microsoft Cloud Security Benchmark. Microsoft states machines must be running the Azure Policy machine configuration extension for this to work, and the feature applies only to machines onboarded with Azure Arc. It is one of the clearer pieces of evidence for hardening in an audit.

A managed extended detection and response service for server workloads, sold separately. Microsoft analysts triage, investigate and contain incidents then hand off with guided steps, proactive threat hunting is included, and you can ask Microsoft experts about specific incidents from the Defender portal. It covers all Plan 1 and Plan 2 alerts where the detection source is Defender for Servers, on Windows and Linux across all supported environments, and DNS alerts are not in scope.

The integration is part of both plans, with automatic onboarding, so servers protected by Defender for Servers get the endpoint detection and response capability. For Defender Experts for Servers specifically, Microsoft states you need Plan 1 or Plan 2 enabled and Defender for Endpoint deployed on your Windows and Linux machines, so deployment state matters there.

Microsoft recommends enabling at the subscription level, while noting you can enable and disable at resource level if you need deployment granularity, within the constraint that Plan 2 cannot be enabled per resource. Deciding the subscription boundary deliberately is worth doing, because it is the unit that determines both coverage and commercial exposure.

Eight to sixteen weeks in a typical estate, and the variable is almost entirely how much Azure Arc onboarding is needed. Enabling the plan and configuring the features is fast. Getting on-premises, AWS and GCP machines Arc-connected, with the machine configuration extension where baselines are required, is what fills the schedule.

We scope per estate, driven by machine count, how many environments are involved, and how much Arc onboarding is required. The plan itself is billed by Microsoft on its own published terms, which we size against your actual server count rather than estimating here. The Arc scoping conversation comes first, because it determines both the timeline and what the plan will deliver.
Before you enable a plan

Fifteen checks that prevent a partial deployment.

The first group is estate reality, the second is prerequisites, and the third is what happens after the thirty day trial starts, since that clock cannot be paused.

Estate reality

  • How many servers, and where?
    Azure, AWS, GCP, on-premises.
  • How many are Windows and how many Linux?
    Both are supported.
  • Are AWS accounts and GCP projects connected?
    That is the onboarding path.
  • Are on-premises machines Arc-enabled?
    Direct onboarding limits Plan 2 features.
  • Which servers genuinely need Plan 2?
    Plan 1 can be enabled per resource.

Prerequisites

  • Is Azure Arc deployment scoped and funded?
    Several Plan 2 features depend on it.
  • Is the machine configuration extension deployed?
    Required for OS baseline assessment.
  • Do you have a Log Analytics workspace?
    Needed for file integrity monitoring.
  • Is a supported collection method in place?
    For the 500 MB ingestion benefit.
  • Is Defender for Endpoint already deployed?
    Required for Defender Experts for Servers.

After enabling

  • Is the 30 day trial timed deliberately?
    It cannot be stopped, paused or extended.
  • Do you want automatic provisioning on?
    The extension installs automatically by default.
  • Who works the alerts?
    Or is Defender Experts for Servers in scope.
  • Who owns remediation of the recommendations?
    Posture findings need an owner.
  • Which resources should be excluded?
    Plan 2 can be disabled per resource.
Related reading

The pages around this one.

Defender for Cloud

The wider posture product Defender for Servers is a plan within.

Learn more

Defender for Endpoint

The endpoint detection and response engine both plans integrate.

Learn more

Server management

The managed service that runs the estate this protects.

Learn more
Next step

Count how many of your servers are Azure Arc connected. That number sets the timeline.

Several of the Plan 2 capabilities people buy the product for are documented as only applying to Arc-onboarded machines. Establishing that number first is the difference between a deployment that delivers and one that explains.

Book a server protection reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Defender for Cloud

Azure posture, and the free tier almost nobody has enabled

Learn more

Defender for Endpoint

Business, Plan 1 or Plan 2, and what each actually gives you

Learn more

Server Management

Windows and Linux server administration

Learn more

Defender Vulnerability Management

Certificates, browser extensions and firmware, not just patching

Learn more

Azure Security Audit

Subscription audit, starting with the free tier you already own

Learn more

Azure Cloud Solutions

Azure landing zone, migration, FinOps, managed

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy