Difference between Microsoft Defender for Cloud and Microsoft Defender Endpoint ?

MyAzQuery 166 Reputation points
2022-08-05T13:33:34.373+00:00

What is the difference between Microsoft Defender for Cloud and Microsoft Defender Endpoint ?

Azure DDos Protection
Azure DDos Protection
An Azure service that provides defense against distributed denial-of-service (DDoS) attacks.
71 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,449 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,654 questions
{count} vote

Accepted answer
  1. Andrew Blumhardt 9,866 Reputation points Microsoft Employee
    2022-08-06T19:36:10.447+00:00

    MDE is a combo of cloud-integrated, enterprise antivirus with a continuous vulnerability assessment that recommends how to make devices mode secure. MDE largely monitors what is happening on devices and servers. MDE also includes manual response and investigation tools. MDE can manage servers, but it is highly focused on end user devices.

    MDFC is designed to protect Azure subscriptions and the resources in those subscriptions. It can be extended to AWS, GCP, and on-prem servers for Server, SQL, and container monitoring.

    MDFC has no antivirus capabilities. The sub-solution, Defender for Servers is only for servers (obviously). MDFC focuses on monitoring how these resources are accessed externally. MDFC also has a vulnerability assessment for resources and servers. The server assessment can use the same TVM engine as MDE. Like MDE, MFDC provides security alerts and hardening recommendations.

    Defender for Servers includes a license for MDE servers. You usually want both on servers (servers need MDE for AV). MDE for (non-server) devices is part of the M365 E3/E5 license.

    16 people found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Ed Harrison 331 Reputation points
    2022-08-05T15:18:33.097+00:00

    Hi @MyAzQuery ,

    Microsoft Defender is the overall "brand" for Microsoft security products, and while these do have similar names as you've spotted they are different products.

    In summary:

    • Microsoft Defender for Endpoint, is an enterprise endpoint security platform - it incorporates things like next generation antivirus, but also include behavioral sensors, leverages cloud based security analytics and threat intelligence in order to provide security for Windows, macOS, Linux, Andoid and iOS endpoints. This link provides a good overview and starting point for more information.
    • Microsoft Defender for Cloud provides "Cloud Security Posture Management" (CSPM), providing a security analysis of all the resources in your cloud estates, and Cloud Workload Protection (CWP) which gives specific protection for your resources such as VMs, cloud storage, databases, security keys, containers, etc. This link provides a starting point on this service.

    One of the workload protections in Defender for Cloud is "Defender for Servers" - one of the ways this provides protection of your servers is by including a license to run Defender for Endpoint on the VM, hence giving you the antivirus and other endpoint protection on that system. However, Defender for Servers also provides other protections such as Just in Time access control and adaptive network hardening.

    In short, if you're looking to provide antivirus and other protections for something like your windows endpoints (i.e. the PCs your employees use on a daily basis) then Defender for Endpoint is the product you're after. If you are looking to protect all your resources in the cloud (Azure, AWS, GCP) then Defender for Cloud is what you're after.

    I hope this helps - if so, please upvote and "mark as answer" so that others will find this in the future.

    -----

    29 people found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.