Lock-lab virtual machines need threat detection, and auditors also require agentless secret and vulnerability scanning. Which Microsoft Defender for Servers selection should the Azure security engineer make?
Select an answer to reveal the explanation.
Short Explanation
Need agentless secret and vuln scans plus the fuller MDVM toolkit? That’s Plan 2. Plan 1 is the leaner Endpoint-centered path—don’t expect the whole agentless toolbox there.
Full Explanation
Microsoft Defender for Servers Plan 2 is the selection when agentless scanning and the broader Microsoft Defender Vulnerability Management feature set are required. Plan 1 is the lower-cost plan centered on Defender for Endpoint as official docs distinguish. Just-in-time VM access is a Domain 3 remote-access control and is not a substitute for choosing Plan 2. Foundational CSPM alone does not deliver that Servers Plan 2 agentless set.