Microsoft Defender for Cloud - for Servers - Pilot deployment

Copper Contributor

Hi Azure experts, 

I am looking at all the different options available for deploying Windows defender for endpoint through Microsoft Defender for Cloud. I have enabled the global defender plan on all my subscriptions but I only want to install this feature on 10-20 servers in a centralized manner. I was looking into different options on how to select a random number of servers but never really saw a potential deployment method to address my problem: Deploy Defender for Cloud (integrated with Defender for Endpoint) on a random set of servers. 

 

Does anybody have any suggestions? Azure Policy is not working at the moment as my servers are in different resource groups or subscriptions. 

2 Replies

A possible solution would be to work with tags and define an Azure Policy based on tag exists, is this something the community recommends?
{
"field": "tags['MemberofPilot]",
"exists": true
}

Most of the Defender for Cloud plans, including Defender for Servers (which onboards servers to MDE), don't support resource level targeting. This means it can only be enabled/disabled at the subscription level.