A Microsoft 365 administrator is reviewing the security posture of their organization. They notice that several Windows Server 2019 machines are reporting vulnerabilities but are not fully onboarded to Microsoft Defender for Endpoint's unified solution for servers. The administrator needs to ensure these servers are fully protected and contribute to the overall security posture. What is the recommended method to onboard these servers to the unified solution?
- AUse the Azure Arc for Servers integration to connect the servers and then enable Defender for Endpoint.
- BDeploy the Defender for Endpoint client via Group Policy Object (GPO) or Microsoft Endpoint Configuration Manager (MECM).
- CManually download and install the onboarding package from the Microsoft 365 Defender portal on each server.
- DInstall the Microsoft Monitoring Agent (MMA) and connect it to a Log Analytics workspace.
Show answer & explanationAnswer & explanation
Correct answer: A. Use the Azure Arc for Servers integration to connect the servers and then enable Defender for Endpoint.
For Windows Server 2019 and newer, the recommended and most integrated method to onboard servers to the unified Microsoft Defender for Endpoint solution is through Azure Arc for Servers. This provides a single control plane for managing and enabling Defender for Endpoint (and other Azure services) across hybrid environments. While options B and D are valid onboarding methods for some scenarios, Azure Arc offers the 'unified solution' integration as highlighted in the question, especially for servers outside of Azure.
Why the other options are wrong
- B. This is a valid method for onboarding Windows client devices or older server OS versions, but for the 'unified solution' on Server 2019, Azure Arc is the preferred integration point for hybrid scenarios.
- C. Manual onboarding is possible but is less scalable and doesn't provide the 'unified solution' management benefits highlighted by Azure Arc for hybrid servers.
- D. The MMA is used for Log Analytics and was previously used for Defender for Cloud's integration, but the question specifies the 'unified solution' for Defender for Endpoint for servers, which now relies on a different model (Azure Arc for non-Azure VMs).
Defender for Endpoint Onboarding with Azure Arc
For Windows Server 2019 and newer, Azure Arc for Servers provides a streamlined and recommended method to onboard servers to Microsoft Defender for Endpoint's unified solution, extending Azure management capabilities to hybrid environments.
- Recommended for Server 2019+ (and Linux servers).
- Extends Azure management to on-premises/other cloud servers.
- Enables Defender for Endpoint as an Azure extension.
- Provides a unified control plane in Azure.
Memory trick: Remember, for 'Servers' to join 'Defender's Unified' team, 'Azure Arc' is the 'Bridge'.