A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Dear @Yashaswini Mahadeva (CP, IN)
The key point is that Microsoft Defender for Endpoint onboarding and Defender for Servers coverage are two separate concepts.
Microsoft Defender for Endpoint can be deployed in different licensing scenarios. A server may be onboarded using a standalone Microsoft Defender for Endpoint license, or it may be protected through Microsoft Defender for Cloud with Defender for Servers.
Therefore, successful MDE onboarding does not, by itself, mean that the server will be counted under the Defender for Servers Plan 1 server count.
If the servers were onboarded directly to MDE using a standalone MDE entitlement, they can be fully operational and visible in the MDE portal without necessarily being included in the Defender for Servers Plan 1 count.
If these servers are expected to be counted under Defender for Servers Plan 1, I would recommend verifying the following:
- Defender for Servers Plan 1 is enabled for the relevant Azure subscription.
- The servers are visible in Defender for Cloud → Inventory.
- The servers are associated with the Azure subscription/resource scope where Defender for Servers is enabled.
- Defender for Servers provisioning is enabled for the relevant resources.
- Sufficient time has passed for Defender for Cloud inventory and licensing information to synchronize.
The first thing to establish is therefore how the servers were onboarded and under which licensing model they are covered. Once this is confirmed, it should be clear whether they are expected to appear in the Defender for Servers Plan 1 server count.
If this answers your query, please click Accept Answer and Upvote if you found it helpful. If you have any further questions, feel free to let us know.