Forum Discussion
Sinisa_Zupanic
Aug 28, 2023Copper Contributor
Microsoft Defender for Server Plan2 is automatic turned on!
Hi Community, on a completely new subscription I create windows server 2022 VM and after a few days I noticed that the MDE.windows extension was installed and Plan2 is turned on for subscription. I ...
CruzAz
Sep 08, 2023Former Employee
Hi Sinisa,
I'm unsure if you found out yet. If you want to know when and how was MDC -servers enabled, you may use this link:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/faq-general#how-can-i-track-who-in-my-organization-enabled-a-microsoft-defender-plan-in-defender-for-cloud-
In general, any Azure activity will be logged for 90 days. So, if this happened within the last 90 days, you might still find out who and how via Azure Activity logs.
Then, the MDE integration is enabled by default with the enhanced features.
From the screenshot you shared, make sure that the scope for Policy is at the MG level, and not only at the subscription level. It could be that it is at a higher level.
I'm unsure if you found out yet. If you want to know when and how was MDC -servers enabled, you may use this link:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/faq-general#how-can-i-track-who-in-my-organization-enabled-a-microsoft-defender-plan-in-defender-for-cloud-
In general, any Azure activity will be logged for 90 days. So, if this happened within the last 90 days, you might still find out who and how via Azure Activity logs.
Then, the MDE integration is enabled by default with the enhanced features.
From the screenshot you shared, make sure that the scope for Policy is at the MG level, and not only at the subscription level. It could be that it is at a higher level.