When to use which portal - MDC or M365 Security Center

Silver Contributor

When an organization has Defender for Endpoint on their Servers, when should they

1. Arc enable them to  use the Defender for Cloud portal

 2. Not bother with Arc and just use the M365 Defender portal

1 Reply

@Dean Gross 

Hey, I would say, it depends.

If you have SCCM in place then you can use tenant attach and sync your on-prem servers via collections to azure ad and into Intune to deploy AV policy settings to them. With that solution you don´t need Defender for Cloud.

In my point of view, if you work more with Azure resources like Azure VM´s and more it makes more sense to bring Defender for Cloud in place. One advantage of Defender for Cloud is that your servers will be automatically onboarded to the Defender Portal.

You can of course add all your servers to Azure Arc and enable them for Defender for Cloud.

Or you have no SCCM and only an on-prem AD / Azure AD you can use the "MDE to enforce security configuration settings from MEM" to bring your Hybrid joined servers to Intune via Microsoft Defender for Endpoint and use that way to deploy Defender AV policies. For that way you also don´t need Azure Arc or Defender for Cloud.

As I said, it depends of your current environment and no matter which channel you use it is important from my point of view to avoid mixing to many possible options up because you get then a lot more portals which you have to maintain.