How to onboard an on-premises Windows Server to Microsoft Defender for Cloud?

You have an on-premises server named Server1 that runs Windows Server. You have an Azure subscription. You need to onboard Server1 to Microsoft Defender for Cloud. What should you install on Server1?

  1. the Azure File Sync agent
  2. the Microsoft Entra provisioning agent
  3. the Device Health Attestation role

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge that non-Azure machines must first be connected via Azure Arc using the Azure Connected Machine agent before Defender for Cloud can manage them; the trap is confusing unrelated Azure agents.

To onboard an on-premises Windows Server to Microsoft Defender for Cloud, you must install the Azure Connected Machine agent (Azure Arc). Community consensus (100% of votes) confirms D, with comments emphasizing that this agent makes the server manageable from Azure.

Choosing Azure File Sync agent or Microsoft Entra provisioning agent is the most common mistake because they are legitimate Azure agents, but neither extends Azure management plane capabilities to on-premises servers for Defender for Cloud.

Community Discussion (5 comments)

sardonique 👍 1 Selected: D
ACMA will make the on prem server azure arc-ed, so Azure will treat it as an internal resource, thus allowing you to deploy policies and agents (such as AMA azure monitoring agent required for defender for cloud) from within the azure portal
BlackCat9588 👍 3 Selected: D
D. the Azure Connected Machine agent
BlackCat9588 👍 2 Selected: D
something wrong in this answer
Webcatman 👍 2 Selected: D
To onboard a on-premise server to azure, you need to install Azure connected machine agent.
Friscini 👍 1 Selected: D
there is something wrong in this answer.....

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Installing the Azure Connected Machine agent (option D) is the mandatory first step for onboarding an on-premises Windows Server to Microsoft Defender for Cloud. This agent connects the server to Azure Arc, making it a managed resource that can receive security policies and extensions like the Azure Monitor Agent, which Defender for Cloud requires for security monitoring. Comments confirm this: 'To onboard a on-premise server to azure, you need to install Azure connected machine agent.' Another comment explains that using Azure Arc allows Azure to treat the on-prem server as an internal resource, enabling policy deployment and agent installation from the portal.

Why the Other Options Are Wrong

Option A, the Azure File Sync agent, is used for synchronizing files with Azure Files shares and has no role in security onboarding. Option B, the Microsoft Entra provisioning agent, is used for synchronizing identity objects to Microsoft Entra ID, not for making a server manageable in Azure. Option C, the Device Health Attestation role, is a Windows Server feature related to attestation of device health, but it does not connect a server to Defender for Cloud or Azure Arc. None of these options enable the required Azure management plane integration that Defender for Cloud needs.

Community Comment Notes

All public comments correctly select D, with one comment noting 'something wrong in this answer' — likely referring to the missing option D in the displayed list. Another comment (AC) usefully clarifies that the Azure Connected Machine Agent makes the server Arc-enabled, allowing Defender for Cloud to deploy required agents such as the Azure Monitoring Agent. The voting distribution (D: 100%) shows strong consensus, and the comments reinforce that the key concept is Azure Arc onboarding.

Official Reference

Exam Strategy

When you see an on-premises server needing onboarding to Defender for Cloud (or any Azure management service), look for the Azure Connected Machine agent — that is the Azure Arc enabler. Remember that Defender for Cloud extends to hybrid machines only after they are Arc-enabled, and other Azure agents are distractors. Eliminate options that serve other purposes (sync, identity provisioning, attestation).

Related Analysis

← Back to AZ-801 Study Guide