Only two lock-lab resource groups need Microsoft Defender for Servers, but billing and enablement are subscription-wide. How should the Azure security engineer think about plan enablement scope?
Select an answer to reveal the explanation.
Short Explanation
Plans light up at the subscription—or the connected AWS account or GCP project—not at a make-believe per-VM storefront SKU. After that, use the product’s real exclusions or per-resource knobs when the docs allow.
Full Explanation
Microsoft Defender for Cloud workload plans are enabled at Azure subscription scope or at connected AWS account / GCP project scope. Operators then use official exclusion and per-resource configuration options where documented; inventing a per-virtual-machine marketplace SKU is not the product model. Sentinel workspace settings and Security Copilot do not define Defender for Servers enablement scope.