Microsoft Defender for Cloud Plan for Azure Servers

Ghulam Abbas 211 Reputation points
2024-07-19T15:01:45.25+00:00

Hi, currently we have the basic Foundational CSPM MS Defender for Cloud plan enabled and also Defender CSPM. We would like to enable the Cloud Workload Protection (CWP) plan 2 for our Azure servers that costs around $15/Server/month. We have around 50 servers in our production subscription and would like to check if there is a way to configure this plan to include only a few of our critical severs for this plan and exclude the rest? Many thanks

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 2,100 Reputation points Microsoft Employee
    2025-08-07T07:19:28.55+00:00

    Hi Ghulam Abbas,

    The only Plan that supports the full enablement (disable and enable) per single VM is P1, P2 supports exclusion only.

    For more details refer to the deployment scope table here - https://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers-select-plan#decide-on-deployment-scope

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.