Where Can You Enable Microsoft Defender for Servers in Azure?

You have a management group named MG1 that contains an Azure subscription named Sub1. Sub1 contains the resources shown in the following table. You need to enable Microsoft Defender for Servers. From the Azure portal, on which two resources can you enable Defender for Servers? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point. - image

  1. RG1
  2. Workspace1 Source Reference Answer
  3. Sub1 Source Reference Answer
  4. MG1
  5. VNet1

Community Votes

BC
100%

100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests understanding of Defender for Servers activation scopes, commonly trapping candidates who confuse resource groups or virtual networks as valid enabling targets.

This question tests your knowledge of deployment scopes for Microsoft Defender for Servers in Azure. The community consensus confirms that both the subscription and Log Analytics workspace are valid entry points for enabling the plan.

Candidates often select Management Groups or Resource Groups, mistakenly assuming hierarchical inheritance allows direct plan activation at those levels instead of subscription or workspace scope.

Community Discussion (5 comments)

Escaruncho 👍 1 Selected: BC
I would go for B and C because it says I need to enable Microsoft Defender for Servers, not just for a computer (which would be VM1, in this case). Bad question, anyway.
BlackCat9588 👍 2 Selected: BC
Not sure. Any link for support?
d08427f 👍 2 Selected: BC
Question is asking regarding 'Defender for Servers' plan, and 'Servers' instead of a specific srv, so ans can only be Sub and Workspace
Azzainthemist 👍 2 Selected: BC
Done on subscription level and then Workspace separately, reference provided by NicolaF supports this
NicolaF 👍 1 Selected: C
According to this: https://learn.microsoft.com/en-us/azure/defender-for-cloud/tutorial-enable-servers-plan you can enable Defender for all Sub1, Workspace1 and VM1. So the question imho is not well posed

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender for Servers can be enabled directly at the subscription level or via the associated Log Analytics workspace. Enabling it at the subscription automatically provisions protection across all supported compute resources within that scope. Alternatively, activating the plan through the workspace achieves the same result by linking the security data collection to Defender’s backend services. Both methods provide complete server protection coverage as required by the scenario.

Why the Other Options Are Wrong

Management groups operate above subscriptions and cannot host Defender plans directly since they only manage policy and assignment rules. Resource groups are logical containers for organizing resources and lack the control plane permissions needed to activate cloud security plans. Virtual networks define network boundaries and routing rules but do not serve as activation targets for monitoring or security solutions. These scopes simply do not expose the Defender for Servers toggle in the Azure portal.

Community Comment Notes

Multiple users confirmed that enabling the plan at the subscription and workspace levels yields identical outcomes, aligning with official documentation. One contributor highlighted that while individual VMs can technically trigger the setup wizard, the question specifically asks for broader resource-level activation. Another user noted the question's phrasing could be clearer but agreed that options B and C remain the most accurate choices based on current platform behavior.

Official Reference

Exam Strategy

Always verify whether a security plan requires subscription-level configuration versus agent-based deployment. When multiple valid scopes exist in Azure, prioritize the highest logical container that matches the question’s stated objective to avoid overcomplicating your selection.

Related Analysis

← Back to AZ-801 Study Guide