Azure Defender for Servers Adaptive Application Controls Support
You have an Azure subscription that contains the virtual machines shown in the following table. You are configuring Microsoft Defender for Servers. You plan to enable adaptive application controls to create an allowlist of known-safe apps on the virtual machines. Which virtual machines support the use of adaptive application controls? - 
Community Votes
75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core trap involves assuming all server editions support advanced Defender features, ignoring that Server Core lacks a GUI and AppLocker conflicts with application allowlisting.
This question tests the compatibility of Microsoft Defender for Servers' adaptive application controls with various Windows Server configurations. The correct answer is (A) because Server Core and AppLocker are incompatible with this specific feature.
Most learners choose (D), incorrectly believing that all listed virtual machines support adaptive application controls due to a misunderstanding of OS limitations and policy conflicts.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Adaptive Application Controls in Microsoft Defender for Servers rely on analyzing process execution data to create allowlists. This feature requires a graphical user interface (GUI) to function effectively and display the recommended actions. VM1 (Windows Server 2019 Datacenter with GUI) and VM2 (Windows Server 2016 Standard with GUI) both meet these requirements. Therefore, they are the only supported options among the choices provided.Why the Other Options Are Wrong
VM3 runs Windows Server 2019 Datacenter Server Core. Since Server Core installations do not have a GUI, they cannot support Adaptive Application Controls, which need the UI to present the allowlist recommendations. VM4 has an AppLocker policy enabled. AppLocker and Adaptive Application Controls serve similar purposes (application whitelisting) and can conflict with each other; thus, VM4 is excluded from support when AppLocker is active.Community Comment Notes
The community is divided, with many votes favoring option D based on the assumption that 'all OS can be protected.' However, detailed comments correctly identify that 'Server Core installations are not supported' and 'Machines using AppLocker are incompatible.' One commenter noted that AppLocker 'may conflict,' while another explicitly stated the GUI requirement, leading to the conclusion that only VM1 and VM2 are valid.Exam Strategy
When studying Defender for Servers, memorize the specific exclusions for its features. Always check if the target VM has a GUI and if conflicting security tools like AppLocker are enabled before selecting 'All of the above'.
Frequently Asked Questions
Why doesn't Server Core support Adaptive Application Controls?
Server Core lacks a Graphical User Interface (GUI), which is required for the feature to present allowlist recommendations and manage settings.
Can AppLocker and Defender Application Control work together?
No, they are incompatible. If AppLocker is enabled, Defender for Servers disables Adaptive Application Controls to prevent policy conflicts.