how do I auto-provision Microsoft Defender for Endpoint new unified solution to new and existing Windows servers 2012R2 and 2016 with Azure Policy

Nadia Hansen 0 Reputation points
2023-03-15T21:13:07.0333333+00:00

I would like to auto-provision Microsoft Defender for Endpoint new unified solution to new and existing Windows servers 2012R2 and 2016 with Azure Policy.

User's image

so instead of saying "partial" i want it to be "on", but I would like to enable it with a policy

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,192 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Akshay-MSFT 16,026 Reputation points Microsoft Employee
    2023-03-17T08:43:24.1033333+00:00

    @Nadia Hansen

    Thank you for posting your query on Microsoft Q&A. This integration is not supported On-Prem Servers:

    Supported environments for Microsoft defender for cloud with defender for endpoint are:

    1. Azure Arc-enabled machines running Windows/Linux
    2. Azure VMs running Linux (supported versions)
    3. Azure VMs running Windows Server 2022, 2019, 2016, 2012 R2, 2008 R2 SP1, Windows 10/11 Enterprise multi-session (formerly Enterprise for Virtual Desktops) Azure VMs running Windows 10 or Windows 11 (except if running Windows 10/11 Enterprise multi-session).
    • we could onboard windows server devices via following steps:
    1. Select Fix to see the components that aren't enabled. User's image
    2. To enable the Unified solution for Windows Server 2012 R2 and 2016 machines, select Enable. Screenshot of enabling the use of the MDE unified solution for Windows Server 2012 R2 and 2016 machines.
      1. To save the changes, select Save at the top of the page and then select Continue in the Settings and monitoring page.

    Microsoft Defender for Cloud will automatically onboard your machines to Microsoft Defender for Endpoint. Onboarding might take up to 12 hours. For new machines created after the integration has been enabled, onboarding takes up to an hour.

    To deploy this from Azure policy you could use Microsoft Defender for Cloud initiatives

    User's image

    Thanks,

    Akshay Kaushik

    Please "Accept the answer" (Yes/No), and share your feedback if the suggestion works as per your business need. This will help us and others in the community as well.