Forum Discussion
Defender for cloud Server configuration
I also onboarded some VMs from on premise over arc and I am very confused because for me it is very hard to understand the pricipes of Defender for Cloud for Servers.
For our Clients we use Defender for Endpoint managed over Intune and the policies are easy to set up and everything is clear.
But when we talk about Defender for Cloud for Servers over Arc everything is different. What I can see in Defender for Cloud and Azure Policy is tons of compliance policies but I am not looking for compliance policies. I just want to configure Defender Antivirus Settings for every machine and I cannot find good information about this.
My hope is big to get useful information here.
Thank you very much in advance.
Have a nice day. Regards
Andreas
So far Intune is the only way I know to configure Defender AV settings. Please check out this link.
https://learn.microsoft.com/en-us/mem/intune/protect/mde-security-integration
- andreasponjavicDec 19, 2023Copper Contributor
migsg Thank you very much for your answer! So far, I know MS don't want us to manage our servers with Intune. They want us to use the Azure capability but if we use guest configuration with azure policy, they will charge 6$ / server / month. Unfortunately, I didn't know this in the beginning of the project.
The solution right now is, similar what you said, to use Intune for the Antivirus Policies. We activated the Management MDE capabilities in M365 Defender. This option is nice in my opinion because Arc onboarded machine are onboarded to Intune automatically over MDE. Maybe I am blind, but this solution is nowhere documented in the Defender for Cloud for Arc enabled machines documentation.
For now, it works well. I am looking forward to seeing how our servers will work with defender..Thank you and I hope this will maybe help others with the same task / project..