MDE is a combo of cloud-integrated, enterprise antivirus with a continuous vulnerability assessment that recommends how to make devices mode secure. MDE largely monitors what is happening on devices and servers. MDE also includes manual response and investigation tools. MDE can manage servers, but it is highly focused on end user devices.

MDFC is designed to protect Azure subscriptions and the resources in those subscriptions. It can be extended to AWS, GCP, and on-prem servers for Server, SQL, and container monitoring.

MDFC has no antivirus capabilities. The sub-solution, Defender for Servers is only for servers (obviously). MDFC focuses on monitoring how these resources are accessed externally. MDFC also has a vulnerability assessment for resources and servers. The server assessment can use the same TVM engine as MDE. Like MDE, MFDC provides security alerts and hardening recommendations.

Defender for Servers includes a license for MDE servers. You usually want both on servers (servers need MDE for AV). MDE for (non-server) devices is part of the M365 E3/E5 license.

Answer from Andrew Blumhardt on learn.microsoft.com
Top answer
1 of 2
18

MDE is a combo of cloud-integrated, enterprise antivirus with a continuous vulnerability assessment that recommends how to make devices mode secure. MDE largely monitors what is happening on devices and servers. MDE also includes manual response and investigation tools. MDE can manage servers, but it is highly focused on end user devices.

MDFC is designed to protect Azure subscriptions and the resources in those subscriptions. It can be extended to AWS, GCP, and on-prem servers for Server, SQL, and container monitoring.

MDFC has no antivirus capabilities. The sub-solution, Defender for Servers is only for servers (obviously). MDFC focuses on monitoring how these resources are accessed externally. MDFC also has a vulnerability assessment for resources and servers. The server assessment can use the same TVM engine as MDE. Like MDE, MFDC provides security alerts and hardening recommendations.

Defender for Servers includes a license for MDE servers. You usually want both on servers (servers need MDE for AV). MDE for (non-server) devices is part of the M365 E3/E5 license.

2 of 2
31

Hi @MyAzQuery ,

Microsoft Defender is the overall "brand" for Microsoft security products, and while these do have similar names as you've spotted they are different products.

In summary:

  • Microsoft Defender for Endpoint, is an enterprise endpoint security platform - it incorporates things like next generation antivirus, but also include behavioral sensors, leverages cloud based security analytics and threat intelligence in order to provide security for Windows, macOS, Linux, Andoid and iOS endpoints. This link provides a good overview and starting point for more information.
  • Microsoft Defender for Cloud provides "Cloud Security Posture Management" (CSPM), providing a security analysis of all the resources in your cloud estates, and Cloud Workload Protection (CWP) which gives specific protection for your resources such as VMs, cloud storage, databases, security keys, containers, etc. This link provides a starting point on this service.

One of the workload protections in Defender for Cloud is "Defender for Servers" - one of the ways this provides protection of your servers is by including a license to run Defender for Endpoint on the VM, hence giving you the antivirus and other endpoint protection on that system. However, Defender for Servers also provides other protections such as Just in Time access control and adaptive network hardening.

In short, if you're looking to provide antivirus and other protections for something like your windows endpoints (i.e. the PCs your employees use on a daily basis) then Defender for Endpoint is the product you're after. If you are looking to protect all your resources in the cloud (Azure, AWS, GCP) then Defender for Cloud is what you're after.

I hope this helps - if so, please upvote and "mark as answer" so that others will find this in the future.

-----

Top answer
1 of 2
3

Hi,

Defender for Cloud is the name of the service. Defender for servers is a feature within that service. For example within Defender for Cloud you also have other features like Defender for Containers, Databases, Storage, App Service, Key Vault and Resource Manager. This can be seen on the pricing. Defender for servers has two SKUs - Plan 1 and Plan 2. It is unclear what are your requirements but overall as Defender for servers is part of Defender for Cloud you do not have to choose between one or the other.

Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

2 of 2
2

Hello!

In general, Microsoft Defender for Cloud (MDC) includes Microsoft Defender for Servers (MDS). Defender for Servers leverages Microsoft Defender for Endpoint (MDE) for its server protection piece, but on top of that, it adds capabilities to Server Monitoring, Access Management, Network Hardening, etc.

If you use the Defender for Server (Defender for Cloud) in Azure, Defender (MDE.Windows/Linux Extension) will install itself automatically on all servers in your subscription. It is called automatic provisioning. You can check this setting via these steps: Microsoft Azure => Microsoft Defender for Cloud => Environment settings => => Defender plans => on the Servers tab choose under Monitoring coverage Settings button => Endpoint protection must be turned on.

If you don't use Defender for Server (Defender for Cloud), then go to https://security.microsoft.com/ and follow these steps: Settings => Endpoints => Device management => Onboarding => select OS, download the script, run it and wait up to 12-24 hours, when you can see MDE.Windows/Linux extension installed on the server.

I recommend this article which explains the difference between these two services:
https://medium.com/microsoftazure/microsoft-defender-endpoint-microsoft-defender-for-cloud-for-servers-53c95d8c8d92

You can also check out the Defender for Servers Plan features:

https://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers-select-plan#plan-features

Note: You must choose a server management model: Defender for Server (Defender for Cloud) or Defender for Endpoint. Because there are different tariffs for services. Defender for Cloud has pay-as-you-go model, but Defender for Endpoint has a model with licenses.


If the above response was helpful, please feel free to "Accept as Answer" and click "Yes" so it can be beneficial to the community.

🌐
Sentia
sentia.ca › Blog › ArtMID › 1133 › ArticleID › 223 › Understanding-the-Difference-Between-Azure-Sentinel-and-Microsoft-Defender
Understanding the Difference Between Azure Sentinel and Microsoft Defender | Sentia | IT Solution Provider | Blog | IT Solution Provider | Toronto | Sentia
January 24, 2024 - Azure Sentinel and Microsoft Defender are both robust security solutions offered by Microsoft, but they have different purposes and features. In this post, we'll explore the key differences between each tool: Microsoft Defender XDR (formerly Microsoft 365 Defender) is a sophisticated security solution that allows you to prevent, discover, and remediate malicious threats from one unified dashboard.
Top answer
1 of 2
1

Microsoft Defender for Cloud is a comprehensive CNAPP solution for securing your enterprise's entire environment. It includes Defender for Servers, Microsoft Defender for IoT, and Microsoft Defender for storage. On the other hand, Microsoft Defender for Cloud Apps is a subset of Microsoft Cloud App Security that provides advanced threat protection for your cloud apps and services. It helps you identify and remediate cloud app security risks, control access to apps based on risk level, and detect and respond to threats. So, while Microsoft Defender for Cloud covers a broader range of security solutions for your enterprise's environment, Microsoft Defender for Cloud Apps focuses specifically on securing your cloud apps and services.

2 of 2
1

Microsoft Defender for Cloud

  1. Scope: Protects cloud workloads and infrastructure across Azure, AWS, GCP, and on-prem hybrid environments.
  2. Primary Focus:
    • Cloud Security Posture Management (CSPM): Assess compliance, misconfigurations, and security posture.
    • Cloud Workload Protection (CWP): Protects VMs, containers, databases, and other resources.
  3. Key Features:
    • Security recommendations for resources.
    • Threat detection for servers, containers, and cloud services.
    • Integration with Azure Policy and regulatory compliance dashboards.
  4. Use Case: If you want to secure IaaS, PaaS, and hybrid workloads, this is your too

Microsoft Defender for Cloud Apps

  1. Scope: Protects SaaS applications and provides visibility into cloud app usage.
  2. Primary Focus:
    • Cloud Access Security Broker (CASB): Discover and control SaaS apps.
    • App Governance: Monitor OAuth apps and risky permissions.
  3. Key Features:
    • Shadow IT discovery (unsanctioned apps).
    • Session controls for real-time monitoring.
    • OAuth app risk assessment and governance.
  4. Use Case: If you want to secure SaaS apps like Microsoft 365, Salesforce, Google Workspace, and manage OAuth permissions, this is your tool.
🌐
LinkedIn
linkedin.com › pulse › whats-difference-between-microsoft-defender-pkjvc
What's the difference between Microsoft Defender for Cloud, Defender for Servers, Defender for Endpoint and Windows Defender Antivirus ?
March 2, 2024 - Microsoft Defender for Cloud:Formerly known as Azure Security Center, Microsoft Defender for Cloud is a cloud-native security solution designed to help organizations protect their cloud workloads and services hosted on platforms such as Azure, AWS, and Google Cloud Platform. It provides security pos
🌐
Reddit
reddit.com › r/azure › would defender for endpoint, or defender for cloud better suit my intentions?
r/AZURE on Reddit: Would Defender for Endpoint, or Defender for Cloud better suit my intentions?
July 1, 2024 -

I've been looking at Microsoft's docs, but I'm getting a bit confused. I want something that will both monitor my Azure virtual machines for malicious activity and deal with any malicious activity. Does Defender for endpoint, or Defender for Cloud fit the bill better? Thanks

🌐
Microsoft Community
techcommunity.microsoft.com › microsoft community hub › communities › topics › itops talk › itops talk blog
What's the difference between Azure Security Center, Azure Defender ...
December 20, 2021 - To add additional security alerts and advanced threat detection, certain types of resources can also be monitored by Azure Defender. The Azure Defender pane inside the Azure Security Center shows you which workloads are protected by Azure Defender or not.
🌐
Microsoft Learn
learn.microsoft.com › en-us › azure › defender-for-cloud › defender-for-cloud-introduction
Microsoft Defender for Cloud Overview - Microsoft Defender for Cloud | Microsoft Learn
Secure your Azure, hybrid, and multicloud resources with Microsoft Defender for Cloud. This cloud-native application protection platform (CNAPP) includes two key capabilities, cloud security posture management (CSPM) and cloud workload protection platform (CWPP).
Find elsewhere
🌐
Cloud4C
cloud4c.com › blogs › azure-security-center-vs-microsoft-defender-vs-sentinel-the-right-fit
Azure Security Center vs Microsoft Defender vs Microsoft Sentinel: Which is Right for You?
Integration with Third-Party Security ... Microsoft Copilot for Security. Security Copilot, powered by Generative AI, provides security professionals with natural language capabilities to streamline investigations and threat hunting within Sentinel. Choosing the right security solution for your Azure environment depends on your specific needs. Here's a comparison table highlighting the key differences between Azure Security Center, Azure Defender, and Microsoft ...
🌐
Petri
petri.com › home › understanding microsoft defender and its many layers
Understanding Microsoft Defender and its Many Layers | Petri
July 1, 2022 - Advanced Threat Protection was gone, and Microsoft Defender was introduced to unify the security offerings across both areas of the Microsoft cloud for IT pros: Microsoft 365 and Azure. The Defender brand has existed since 2005, first seen in anti-spyware software for Windows XP and Vista called Windows Defender. Defender, over fifteen years later, is wildly more comprehensive and diverse in its scope. The difference between Defender then and now reflects the changes we’ve seen in Microsoft as a whole over that same time: security isn’t perceived as an afterthought, there is no dogmatic exclusivity to one platform, and it’s all cloud-first.
🌐
Microsoft Learn
learn.microsoft.com › en-us › answers › questions › 1845817 › azure-defender-for-cloud-portal-vs-microsoft-defen
Azure Defender for Cloud Portal vs Microsoft Defender Portal - Microsoft Q&A
A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations ... Thanks for providing your feedback. Let me know if you have additional details around my follow-up query. Thanks again for your valuable feedback! ... Defender for Servers is available only for Windows 11 multi-session VMs - as per https://learn.microsoft.com/en-us/azure/defender-for-cloud/support-matrix-defender-for-servers
🌐
PeerSpot
peerspot.com › home
Compare Microsoft Defender for Cloud vs Microsoft Defender XDR
July 27, 2025 - Microsoft Defender XDR holds an upper hand due to its advanced threat detection, prevention, and automated response capabilities. Features: Microsoft Defender for Cloud integrates seamlessly into the Azure ecosystem, offering extensive visibility ...
🌐
Sam's Corner
samilamppu.com › 2020 › 11 › 24 › microsoft-365-defender-vs-azure-sentinel-which-one-to-use
Microsoft 365 Defender vs Azure Sentinel – Which One To Use?
July 30, 2022 - In a nutshell, M365 Defender protects M365 workloads and Azure Defender protects Azure workloads, on-premises & resources in 3rd party clouds (Threat protection). Before moving forward let’s familiar with the new names of M365 security solutions ...
🌐
Microsoft Community
techcommunity.microsoft.com › microsoft community hub › communities › products › microsoft security › microsoft defender for cloud › microsoft defender for cloud blog
A new name for multi-cloud security: Microsoft Defender for Cloud ...
February 1, 2022 - Last year at Microsoft Ignite, we introduced a first set of capabilities to support multi-cloud environments with the launch of AWS and GCP connectors, using Azure Arc. This year we announced native CSPM support for AWS and significant enhancements in onboarding AWS workloads, as well as support for Amazon EKS Kubernetes clusters and AWS EC2. As part of this shift to support multi-cloud environments natively and better reflect the integrated capabilities of our security offering that help customers secure any cloud platform, we unified the two product names under the new name Microsoft Defender for Cloud.
🌐
Wizard Cyber
wizardcyber.com › blog › understanding the different versions of microsoft defender
Understanding the Different Versions of Microsoft Defender
May 30, 2025 - Previously known as Azure Advanced Threat Protection (noticing a trend here?), Microsoft Defender for Identity actively protects on-premises active directories from compromise by employing cloud-based learning algorithms.
🌐
Reddit
reddit.com › r/azure › what is the difference between azure sentinel and azure defender?
What is the Difference between Azure Sentinel and Azure Defender? : r/AZURE
August 21, 2023 - The difference is that there is no service right now called Azure Defender while Azure Sentinel still exists. Azure Defender and Security Center joined to form Defender for Cloud which is what we have today. It provides CSPM and CWPP features to Azure and multi cloud environments.
🌐
Check Point Software
checkpoint.com › home › secure the cloud › what is azure security? › microsoft defender for cloud
Microsoft Defender for Cloud (Azure Security Center)
December 26, 2024 - Microsoft Defender for Cloud, formerly known as Azure Security Center, offers Azure security protection, but extends beyond this to provide protection to all public and hybrid cloud environments, and that protection can be further enhanced by ...
🌐
Microsoft Learn
learn.microsoft.com › en-us › azure › architecture › solution-ideas › articles › microsoft-365-defender-security-integrate-azure
Integrate Azure and Microsoft Defender XDR security services - Azure Architecture Center | Microsoft Learn
For more information, see Azure Monitor overview. Microsoft Defender for Cloud delivers recommendations for virtual machines (VMs), storage, applications, and other resources, that help an IT environment to be compliant with various regulatory standards, such as ISO and PCI.
🌐
Argon Systems
argonsys.com › home › msft articles › what's the difference between azure security center, azure defender and azure sentinel?
What's the difference between Azure Security Center, Azure Defender and Azure Sentinel? - Argon Systems
July 26, 2025 - Azure Security Center – Security Posture ManagementAzure Defender – Advanced Workload ProtectionAzure Sentinel – Security Information Event Management + Security Orchestration Automated ResponseSummary It’s common to have a pre-defined perspective when you hear the word “security”. Some people think of applications being configured correctly or insecure coding practices.