Forum Discussion

seth's avatar
seth
Iron Contributor
Oct 02, 2022

Defender for Endpoint Server standalone license

As of September 1, Microsoft has removed the Defender for Endpoint on Servers P1 and P2 licenses, forcing on-premises customers to use Azure ARC / Defender for Cloud!


Onboarding to Azure ARC is not always possible, another agent is required and it requires a huge effort for the management of the subscription, security and assets.

 

Microsoft will lose EDR customers... This will also show up in the client licenses of Defender for Endpoint. If Microsoft does not want on-premises server customers in their EDR solutions, the customers will not go with two EDR solutions but leave Microsoft and choose antoher EDR / XDR solution for server AND clients. How does Microsoft imagine it if different MSPs provide services for the customer and on premises and Azure are strictly separated? Should the Azure partner then have access to the on-premises systems. That won't happen.

 

Another bad decision for customers, partners and lastly for Microsoft.

 

Please revert your decision and make the Defender for Endpoint Server P2 License available again through CSP, EA and Direct. 

14 Replies

  • LS957458's avatar
    LS957458
    Copper Contributor

    seth  Have you learned anything new since your previous posts on how to obtain endpoint for server licensing?  I'm trying to get MDE P1 for servers but defender for cloud is forcing me to P2.

    • Keith_Powell's avatar
      Keith_Powell
      Icon for Microsoft rankMicrosoft

      LS957458 - You can only have 1 type of MDS (Microsoft Defender for Server, which is part of the Microsoft Defender for Cloud solutions) plan per Azure Subscription. So, if you have already deployed MDS Plan 2 within your subscription, you won't be able to 'downgrade' other servers to Plan 1. The reverse holds true as well. 

       

        So, if you want to have a mixture of Plan 1 and Plan for your on-premises and/or in the Cloud (Azure, AWS, and/or GCP), then you need 2 Azure Subscriptions for that same single tenant. Your licensing specialist, MSFT Account Team, and/or your reseller can help you with that process.  

  • seth,  I work with the major \ strategic customers and we are still selling MDE P2 for servers on Enterprise Agreements.  The Azure offering is a elevated offering provide the core MDE capability + advanced capabilities such as vulnerability management and file integrity monitoring. 

    • seth's avatar
      seth
      Iron Contributor
      That's nice that you speak for your EA Bubble. But it is no longer available in Direct and CSP for new customers / renew subscriptions. Not everyone wants or can sign an EA. Even more stupid was the idea to make it different in the contracts.
      • JonRuiz's avatar
        JonRuiz
        Icon for Microsoft rankMicrosoft

        HI Seth,

        Is this for your personal use or for a small to medium business? What are your reasons that you feel having an enterprise agreement is prohibitive?   If you are Microsoft partner you can obtain solutions via the partner program.  Otherwise, an EA can be economical even for the smallest customers.   I recommend speaking to your reseller. 

        Here is the link to the descriptions of the available server plans:

        Overview of Microsoft Defender for Servers | Microsoft Learn

        Note that Plan 1 for Servers actually includes MDE P2 and it is about $4.91 for 730 hours per month (ie. 100% usage).     Plan 2 for servers offers a treasure trove of additional capabilities that you can read about in the link above - it's retail is $14.60 for 730 hours per month. 

    • JonRuiz's avatar
      JonRuiz
      Icon for Microsoft rankMicrosoft
      The product name is Defender Endpoint Server and the part # is 1NZ-00004

Resources