Edit

Migrate servers from Microsoft Defender for Endpoint to Microsoft Defender for Servers

This article describes how to migrate your servers from Defender for Endpoint to Defender for Servers. Before you begin, review the prerequisites and migration steps for your server type.

Defender for Endpoint is an endpoint security platform. It helps organizations prevent, detect, and respond to advanced threats. With a Defender for Endpoint for servers license, you can onboard a server to Defender for Endpoint.

Defender for Servers is part of Microsoft Defender for Cloud. Defender for Cloud provides cloud security posture management (CSPM) and cloud workload protection (CWP). It finds weak spots in your cloud setup and helps protect workloads across multicloud and hybrid environments.

Both products offer server protection, but Defender for Servers is our primary solution to protect servers.

How do I migrate my servers from Defender for Endpoint to Defender for Cloud?

If you have servers onboarded to Defender for Endpoint, the migration steps depend on the machine type. However, all machines share a set of prerequisites. Defender for Cloud is a subscription-based service in the Microsoft Azure portal. You must enable Defender for Cloud and a Defender for Servers plan (Plan 1 or Plan 2) on your Azure subscriptions.

Before you enable Defender for Cloud

Before you enable Defender for Cloud, it's important to know how to manage antivirus policies and define any needed exclusions. See the following articles:

Enable Defender for Servers for Azure VMs and non-Azure machines

To enable Defender for Servers for Azure VMs and non-Azure servers connected through Azure Arc-enabled servers, follow this guidance:

  1. If you aren't already using Azure, plan your environment following the Azure Well-Architected Framework.

  2. Enable Defender for Cloud on your subscription.

  3. Enable a Defender for Servers plan on your subscription. In case you're using Defender for Servers Plan 2, make sure to also enable it on the Log Analytics workspace your machines are connected to. Enabling Defender for Servers Plan 2 on the Log Analytics workspace lets you use optional features, like File Integrity Monitoring.

  4. Make sure the Defender for Endpoint integration is enabled on your subscription. If you have preexisting Azure subscriptions, you might see one or both opt-in buttons for Allow MDE access to EWACS data and Allow MDE Unified Agent for EWACS as shown in the following image:

    Screenshot that shows how to enable Defender for Endpoint integration.

    If you see either of these opt-in buttons in your environment, make sure to enable integration for both. On new subscriptions, both options are enabled by default, and the buttons don't appear.

  5. If you plan to use Azure Arc, check that the connectivity requirements are met. Defender for Cloud requires all on-premises and non-Azure machines to connect through the Azure Arc agent. Azure Arc doesn't support every operating system that Defender for Endpoint supports. For planning help, see Azure Arc deployments.

  6. (Recommended) If you want to see vulnerability findings in Defender for Cloud, make sure to enable vulnerability assessment in Defender for Cloud.

    Screenshot that shows how to enable vulnerability management.

How do I migrate existing Azure VMs to Defender for Cloud?

For Azure VMs, no extra steps are required. These devices are automatically onboarded to Defender for Cloud because of the native integration between the Azure platform and Defender for Cloud.

See Connect your non-Azure machines to Microsoft Defender for Cloud with Defender for Endpoint.

How do I migrate on-premises machines to Defender for Servers?

For on-premises machines, you have several onboarding options:

How do I migrate VMs from AWS or GCP environments?

If you're using Amazon Web Services (AWS) or Google Cloud Platform (GCP), follow these steps to migrate those VMs:

  1. Create a multicloud connector on your subscription. To learn more, see AWS accounts or GCP projects.

  2. On the connector, turn on Defender for Servers for AWS connectors or GCP connectors.

  3. Turn on autoprovisioning on the connector for the Azure Arc agent, the Defender for Endpoint extension, and Vulnerability Assessment. If you use Defender for Servers Plan 2, also turn on agentless machine scanning.

    Screenshot that shows how to enable autoprovisioning for Azure Arc agent.

To learn more about multicloud support and onboarding non-Azure machines, see Defender for Cloud's multicloud capabilities and Connect your non-Azure machines to Microsoft Defender for Cloud.

What happens once all migration steps are completed?

After you complete the migration steps, Defender for Cloud deploys the Defender for Endpoint extension for Windows (MDE.Windows) or Linux (MDE.Linux) to your Azure VMs and Arc-connected non-Azure machines. This includes VMs in AWS and GCP.

The extension serves as a management interface. It wraps the Defender for Endpoint install scripts inside the operating system and reports its status to the Azure management plane. If Defender for Endpoint is already installed, the process detects it and connects it to Defender for Cloud by adding Defender for Endpoint service tags.

Some devices might run Windows Server 2012 R2 or Windows Server 2016 with the legacy, Log Analytics-based Defender for Endpoint solution. For these devices, Defender for Cloud deploys the Defender for Endpoint unified solution. It then stops and disables the legacy process (MsSense.exe) on those machines.

See also

For more details, see these related articles: