Blog Post

Small and Medium Business Blog
4 MIN READ

Server security made simple for small businesses

Jon Maunder's avatar
Jon Maunder
Icon for Microsoft rankMicrosoft
Nov 08, 2022

Now more than ever, small businesses are being affected by cyber-attacks—and servers are a common target. They represent an opportunity to access your business from the outside through potentially vulnerable internet-facing services such as web applications and email.

 

As attackers become more sophisticated, traditional signature-based antivirus can’t keep up. A holistic approach is needed to identify, protect, detect, and respond to threats to your servers. You need to elevate your endpoint security beyond traditional antivirus, with a simple and cost-effective solution. This is where Microsoft Defender for Business can help.

 

Server security in Defender for Business is now generally available as an add-on license to Microsoft 365 Business Premium and Defender for Business subscriptions, for customers who have up to 60 server instances within their environment.

 

The Microsoft Defender for Business server add-on brings Windows Server and Linux operating system support to Defender for Business for $3 per server instance per month. It’s available to try and buy now from https://aka.ms/DefenderforBusiness, or from the Microsoft Admin Center

Server security is now available within Microsoft Defender for Business with a new add-on license.

 

We launched a preview of server security in Defender for Business on July 13th 2022. Preview is now complete and if you onboarded servers during this time you have two options:

  1. Purchase Defender for Business server add-on for $3 per server instance per month to continue securing servers. The service will continue to protect servers uninterrupted without the need for re-onboarding or configuration changes.
  2. Offboard servers from Defender for Business.

Identify and fix vulnerabilities

Proactive hardening of servers is a critical task to secure them from outside threats. To reduce risk, you should keep them up to date with patches, ensure software is configured correctly, and monitor their state 24/7.


Onboarding devices and servers into Defender for Business is a fast way to understand the security posture of your endpoints. Threat and vulnerability management (TVM) equips you with insights into risks that are impacting your devices and servers. Continuous vulnerability discovery and intelligent prioritization brings together business and threat context to provide you with actionable recommendations to improve security posture.


With TVM included within Defender for Business, it becomes easier than ever to identify your environment’s weaknesses and act quickly to fix vulnerabilities. Learn more about Threat and Vulnerability Management in Defender for Business.

Threat and Vulnerability Management dashboard provides security recommendations for devices and servers in your business.

 

Protect, detect, and respond

Security is activated out-of-the-box with Defender for Business through the application of default policies that help protect devices and servers from day one. Endpoint Detection and Response capabilities will help monitor for threats on these endpoints to ensure incidents can be tracked across users, files, processes, devices, and servers. Automated incident response acts like your own 24/7 security operator helping to remediate issues on your behalf, saving time and allowing you to focus on priority actions across your environment.

 

Let’s take a look at how this works for server operating systems.

 

Windows Servers

You can manage Windows Server and Windows client devices with the same wizard-driven onboarding, antivirus, and firewall settings directly from the Microsoft 365 Defender security admin portal. Simplified security admin experiences are available when using Windows Server 2012R2 and later. You can onboard servers using Microsoft Intune (included with Microsoft 365 Business Premium), local scripts, Group Policy, or with Configuration Manager. Learn more at Onboard devices to Microsoft Defender for Business.

 

Linux servers

You can use deployment scripts to onboard Linux servers into Defender for Business. Alternatively, you can integrate these scripts to an existing management platform such as Chef, Puppet, and Ansible to onboard your servers. Recommended security settings are also activated out-of-the-box, and supported Linux versions can be found here. Learn more at Onboard devices to Microsoft Defender for Business.

Protect, detect, and respond to threats with automated investigation and remediation built in.

If you are a Microsoft CSP partner using Microsoft 365 Lighthouse you can view security alerts, incidents, and the device list across multiple customers from a single admin experience. With the addition of servers into Defender for Business, you will now see the incident and alert information displayed on the Device Security page.

 

Feedback and community engagement

We want you to use Defender for Business and tell us about your experience. Your input is important to us, we’re listening, and we want your feedback. Here are some ways you can engage with us:

  1. In-product help and support
  2. SMB Tech Community – engage the product team for questions and feedback.
  3. Yammer for Microsoft 365 Partners


Learn more

Secure your servers today with the Defender for Business servers add-on. Learn more using these other resources:

For customers

For IT partners

FAQ

Updated Nov 08, 2022
Version 2.0
  • fazilats's avatar
    fazilats
    Copper Contributor

    Hello, 

     

    Can partners still benefit from it even though they don't have achieved the Business Application Solution Designation Area?

  • HeirEllie's avatar
    HeirEllie
    Copper Contributor
    Crap I have to rewrite my reply all over again I do have the security handbook manual saved on to my phone and my computer which is pretty lengthy and it does cover sort of in real life situation where just in real life you have to be wary and by the way since I have to retype this part of this including this paragraph is generated using Google software voice to text but to touch up on security and I kind of want to just reply to this since it pertains to security and I don't want to have to make a topic because you guys are talking about software my life is not that progressed yet even with just the Microsoft partner program alone I was inducted like mid-november and I've only read like the first chapter of the security handbook manual because it does not apply to me yet but I have to do mention this in and it's also a question so I know that my question does not belong as a reply but it's very important where I would probably be very irresponsible if I were on the Forum just so happens that I'm on the form right now and I were to not ask : how does a startup acquire an office? I'll keep this short : I ask that because as usual preserving my way of life and livelihood is seemingly always impossibility difficult and proving that has now become easy where I can tell you that it's gotten worse and more difficult all around and together, with very little reward or return for inconveniences, that filing a discrimination report to HUD? I would have just taken the no action no response but it actually got worse afterwards. So I need an office so I'm not so vulnerable, prone to the dangers not only of the elements, and actually, more so from the threat of other humans.
  • AndiW666's avatar
    AndiW666
    Copper Contributor

    Hi,

     

    following to the post from Claudio Stallone above, i would like to know if ths limit of 60 server is hard coded or if i can license more server with the add-on

    Microsoft Defender for Business servers is an add-on for Microsoft 365 Business Premium or Microsoft Defender for Business standalone product. It helps protect Windows and Linux servers against cybersecurity threats, including malware and ransomware, in an easy-to-use, cost-effective package. Defender for Business servers is now available to try and buy. Learn more.

  • CharlieCharles1's avatar
    CharlieCharles1
    Copper Contributor

    I would think that sandboxing a server with end to end sophisticated encryption is the solution.

  • ImranatKSA's avatar
    ImranatKSA
    Copper Contributor

    Hi everyone, 

     

    I don't know this is the right place or not, but we face this challenge most of the time, customers are asking for Battle Cards. Which is a very easy way to have apple to apple comparison between 2 products. I'm talking about overall defender product line. Please guide me in right direction. 

     

  • Hi Jon Maunder ,

    The documentation explains that there is a limit of licenses per subscription:
    There is a limit of 60 Microsoft Defender for Business Server licenses per Microsoft 365 Business Premium or Defender for Business subscription.

    Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-business/get-defender-business-servers?view=o365-worldwide 

     

    The terms state the following:
    A separate license is required for each OSE, up to a maximum of 60 licenses per customer.

    Source: https://www.microsoft.com/licensing/terms/productoffering/MicrosoftDefenderforBusinessservers/MCA 

     

    So a tenant can only license 60 servers with "Microsoft Defender for Business Server". Which is rather little. Are there plans to increase this number?

  • mbaybarsk's avatar
    mbaybarsk
    Copper Contributor

    "Server security in Defender for Business is now generally available as an add-on license to Microsoft 365 Business Premium and Defender for Business subscriptions, for customers who have up to 60 server instances within their environment."

    I wish the limit was 300, like the number of client licenses. We have more than 60 servers for a similar number of user licenses and this limitation really discourages me to leave my other endpoint protection tools/vulnerability scanners and switch to MS Defender completely.  I don't want to run a separate set of tools for servers vs clients, if at all possible. 

  • security101's avatar
    security101
    Copper Contributor

    Great news 😀

    I assume servers has to be Azure joined, to be enrolled into Defender?