Some lock-lab virtual machines run Microsoft Defender for Endpoint; others rely on agentless-only coverage under Servers Plan 2. How do Microsoft Defender Vulnerability Management findings reach Defender for Cloud?
Select an answer to reveal the explanation.
Short Explanation
MDVM can ride agentless snapshots, Defender for Endpoint, or both—depending on the Servers plan. Nobody is forcing a third mystery agent onto every lock-lab VM.
Full Explanation
Microsoft Defender Vulnerability Management assessment paths for Azure virtual machines include agentless scanning and/or Microsoft Defender for Endpoint based on the Defender for Servers plan. A separate third assessment agent is not required. Defender for Office 365 and Security Copilot are not MDVM assessment paths, and Defender for Endpoint appears here only as the Servers/MDVM integration—not as a first-class Defender XDR specialty skill.