SOLVED

Enroll only selected servers in Azure Defender

%3CLINGO-SUB%20id%3D%22lingo-sub-2267722%22%20slang%3D%22en-US%22%3EEnroll%20only%20selected%20servers%20in%20Azure%20Defender%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2267722%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Team%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20existing%20LA%20Workspace%20which%20I%20use%20for%20Sentinel%2C%20so%20the%20MMA%20is%20installed%20on%20our%20on-premise%20servers.%3C%2FP%3E%3CP%3ENow%20I%20would%20like%20to%20enable%20this%20workspace%20in%20Azure%20Defender%2C%20but%20I'll%20only%20want%20to%20add%20some%20of%20the%20servers%20in%20Azure%20Defender(paid%20version)%2C%20is%20there%20any%20way%20to%20do%20this%20or%20do%20you%20need%20another%20workspace%20for%20the%20servers%20I%20would%20like%20to%20add%20to%20Azure%20Defender%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi Team,

 

I have a existing LA Workspace which I use for Sentinel, so the MMA is installed on our on-premise servers.

Now I would like to enable this workspace in Azure Defender, but I'll only want to add some of the servers in Azure Defender(paid version), is there any way to do this or do you need another workspace for the servers I would like to add to Azure Defender?

2 Replies
best response confirmed by khelbo (New Contributor)
Solution

Hi @khelbo 

 

Even though it's possible to enable AzDefender for Servers at the workspace level, it's highly recommended to enable it at the subscription level, otherwise you won't get some additional features like JIT, Application controls, MDE, etc.
Azure Defender for servers - the benefits and features | Microsoft Docs


Also, its not currently possible to enable Defender for a subset of servers connected to ASC, this is something we are considering adding in the future.

Azure Security Center FAQ - data collection and agents | Microsoft Docs

 

 

You cannot enable Azure Defender for only selected servers on your subscription. Please read the article on : https://docs.microsoft.com/en-us/azure/security-center/security-center-get-started#:~:text=To%20enab....

Azure Defender / Security Center enables on your subscription level. Not with individual components.