Offboarding VMs from Defender for Servers Plan 2

PM 0 Reputation points
2025-05-01T10:02:46.0366667+00:00

After enabling Defender for Servers Plan 2 on a subscription for testing, the plan has been deactivated; however, the servers are still visible in the Defender for Server Portal. In the Azure portal, the MDE.Windows extension remains installed on the VM.

It was expected that deactivating the plan in MDC would automatically offboard the VMs. Is there a required step in between this process? Documentation on this topic seems to be lacking.

Assistance with this issue would be greatly appreciated.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,545 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Jose Benjamin Solis Nolasco 1,836 Reputation points
    2025-05-01T12:48:32.4833333+00:00

    Good morning, I hope you are doing well,

    You can read a little bit more about this here https://learn.microsoft.com/en-us/defender-endpoint/offboard-machines

    Also I made this guide for you;

    To offboard VMs from Defender for Servers Plan 2, follow these steps:

    Uninstall the MDE.Windows extension:

    • In the Azure portal, navigate to the VM.
      • Select Extensions under Settings.
        • Find MDE.Windows and select Uninstall 1.
        Offboard the VM from Defender for Endpoint:
        - In the **Microsoft Defender portal**, go to **Settings** > **Offboard**.
        
           - Select the operating system of the VM and follow the prompts to complete the offboarding process **1** **2**.
        
           **Verify the offboarding**:
        
              - Check the **Event Viewer** on the VM for events from the **WDATPOnboarding** source to confirm successful offboarding **2**.
        
              **Remove policies and configurations**:
        
                 - If you used **Group Policy**, **Configuration Manager**, or **Mobile Device Management (MDM)** tools for onboarding, ensure you remove any policies or configurations related to Defender **1** **2**.
        

    These steps should help ensure that the VMs are fully offboarded from Defender for Servers Plan 2. If you encounter any issues or need further assistance, you can refer to the official documentation

    😊 If my answer helped you resolve your issue, please consider marking it as the correct answer. This helps others in the community find solutions more easily. Thanks!

    1 person found this answer helpful.
    0 comments No comments

  2. Navya 18,840 Reputation points Microsoft External Staff Moderator
    2025-05-05T14:21:11.54+00:00

    Hi @PM

    I understand that you enabled Defender for Servers Plan 2 on a subscription for testing, and later deactivated it. However, you're still seeing servers listed in the Defender for Servers portal.

    When you enable the Defender for Servers plan on a subscription, the native Defender for Endpoint integration in Defender for Cloud automatically deploys the Defender for Endpoint agent on supported machines as needed. This automatic onboarding installs the MDE.Windows or MDE.Linux extension, depending on the operating system.

    Deactivating Defender for Servers Plan 2 does not automatically offboard virtual machines (VMs) or remove installed agents or extensions such as the MDE.Windows extension. Disabling Plan 2 only stops further billing and deployment; it does not remove existing agents or offboard the VM from Microsoft Defender for Endpoint (MDE).

    To offboard the servers, you must first delete the MDE.Windows or MDE.Linux extension from the VM and then follow the offboarding process.

    For detailed instructions, refer to the official documentation: https://learn.microsoft.com/en-us/defender-endpoint/onboard-server#offboard-windows-servers

    Hope this helps. Do let us know if you any further queries.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.