<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CWPP on Nicola Suter</title><link>https://nicolasuter.ch/tags/cwpp/</link><description>Recent content in CWPP on Nicola Suter</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>© 2026 Nicola Suter</copyright><lastBuildDate>Sat, 03 Oct 2026 20:37:03 +0000</lastBuildDate><atom:link href="https://nicolasuter.ch/tags/cwpp/rss.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Defender for Servers Decompiled</title><link>https://nicolasuter.ch/defender-for-servers-decompiled/</link><pubDate>Sat, 03 Oct 2026 20:37:03 +0000</pubDate><guid>https://nicolasuter.ch/defender-for-servers-decompiled/</guid><description>&lt;p&gt;When speaking with customers and colleagues, I often encounter questions and misconceptions about Defender for Servers in Microsoft Defender for Cloud. In this post, I explore these questions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Why should I care about Defender for Servers?&lt;/li&gt;
&lt;li&gt;How should I onboard my servers to Microsoft Defender for Servers?&lt;/li&gt;
&lt;li&gt;What happens under the hood when I onboard servers?&lt;/li&gt;
&lt;li&gt;How can I selectively deploy Defender for Servers (e.g., for a pilot)?&lt;/li&gt;
&lt;li&gt;How can I enforce and maintain full coverage of Defender for Servers?&lt;/li&gt;
&lt;li&gt;How can I monitor and query Defender for Servers coverage?&lt;/li&gt;
&lt;/ul&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="auto"
 alt="Defender for Server Confusion"
 width="2980"
 height="1652"
 src="https://nicolasuter.ch/defender-for-servers-decompiled/meme_hu_faf426a335ca2958.png"
 srcset="https://nicolasuter.ch/defender-for-servers-decompiled/meme_hu_faf426a335ca2958.png 800w, https://nicolasuter.ch/defender-for-servers-decompiled/meme_hu_c287ab41c2de71c9.png 1280w"
 sizes="(min-width: 768px) 50vw, 65vw"
 data-zoom-src="https://nicolasuter.ch/defender-for-servers-decompiled/meme.png"&gt;&lt;figcaption&gt;Typical confusion of Defender for Servers&lt;/figcaption&gt;&lt;/figure&gt;

&lt;h2 class="relative group"&gt;Defender for Servers Plans and Licensing
 &lt;div id="defender-for-servers-plans-and-licensing" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#defender-for-servers-plans-and-licensing" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;While client devices in Microsoft Defender for Endpoint (MDE) are usually licensed through Microsoft 365 subscriptions such as Microsoft 365 E5, servers do not benefit from this licensing model. Instead, server licensing follows the Azure consumption model.&lt;/p&gt;
&lt;p&gt;If you work with the Microsoft account team, you might also be able to obtain &lt;em&gt;Microsoft Defender for Endpoint Server&lt;/em&gt; licenses. These are not consumption-based, so they do not require an Azure subscription and are usually part of enterprise agreements.&lt;/p&gt;</description></item></channel></rss>