Choosing between Defender for Endpoint and Defender for Server for servers with no internet connectivity

milo last 20 Reputation points
2024-04-23T07:49:38.81+00:00

We are planning to migrate from Symantec® Endpoint Security to Microsoft, specifically looking for EDR and XDR features for our On Prem servers that have no connectivity to the internet. Should we use Defender for Endpoint or Defender for Servers? We are also considering if servers can connect using proxy.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,201 questions
0 comments No comments
{count} votes

Accepted answer
  1. James Hamil 21,851 Reputation points Microsoft Employee
    2024-04-25T20:12:46.3666667+00:00

    Hi @milo last , Defender for Endpoint and Defender for Servers both provide endpoint protection, but they have different features and capabilities. Defender for Endpoint is a cloud-based solution that provides advanced endpoint protection, including endpoint detection and response (EDR) capabilities. It requires an internet connection to function properly. On the other hand, Defender for Servers is an on-premises solution that provides endpoint protection for servers. It does not require an internet connection to function properly.

    If your servers have no connectivity to the internet, Defender for Servers would be the better choice for you. It provides endpoint protection for servers without requiring an internet connection. However, if you have some servers that can connect using a proxy, you can use Defender for Endpoint for those servers.

    It's important to note that if you choose Defender for Servers, you will not have access to the advanced EDR capabilities provided by Defender for Endpoint. However, Defender for Servers does provide basic endpoint protection for servers, including antivirus and antimalware protection.

    If you have servers with no internet connectivity, Defender for Servers would be the better choice for you. If you have some servers that can connect using a proxy, you can use Defender for Endpoint for those servers.

    Please let me know if you have any questions and I can help you further.

    If this answer helps you please mark "Accept Answer" so other users can reference it.

    Thank you,

    James

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful