Configure Microsoft Defender Plans, Tiers, and Pricing¶
Last updated: 2026-07-27
Use this reference before enabling a Defender plan. Product capabilities, resource eligibility, regional availability, and prices can vary by plan, cloud, resource type, and licensing agreement.
Configure a Defender for Cloud plan¶
- Open Microsoft Defender for Cloud.
- Select Environment settings, then select the subscription, management group, AWS account, or GCP project hierarchy that owns the resources.
- Open Defender plans, choose the required plan, and review its included capabilities and billed components.
- Select Settings & monitoring to configure supported extensions, data collection, agentless scanning, Defender for Endpoint integration, and monitoring options.
- Save the change, verify the plan state, and confirm coverage before applying the same setting to a broader scope.
For the current portal workflow and plan-management prerequisites, use Enable enhanced security features.
Choose the plan or tier¶
| Decision | Use this source |
|---|---|
| Compare Defender for Cloud workload plans, prerequisites, and supported resources | Defender for Cloud support matrix |
| Compare Defender for Servers Plan 1 and Plan 2 | Plan Defender for Servers |
| Decide whether foundational CSPM or Defender CSPM is required | CSPM in Defender for Cloud |
| Confirm Microsoft 365 and Defender XDR license entitlements | Microsoft 365 service descriptions |
Check regional availability and eligibility¶
Before enabling a plan, use the Defender for Cloud support matrix to verify the resource type, cloud, region, operating system, and required extension or connector. For AWS and Google Cloud, also confirm connector permissions and supported service regions before a pilot.
Estimate and monitor cost¶
Use live pricing and actual resource counts rather than documentation examples:
- Defender for Cloud pricing
- Defender for Cloud cost calculator
- Azure pricing calculator
- Azure Cost Management
Capture the selected plan, scope, billing meter, region, resource count, and assumptions in the deployment record. Review the estimate after the pilot using actual charges, then establish budgets and anomaly alerts before broad rollout.
Operational decisions¶
- Document the business purpose, eligible resources, regional assumptions, and approval owner before changing any plan at management-group or connector scope.
- Pilot settings that introduce agents, scanning, or data collection separately from the base plan so coverage, operational impact, and cost remain measurable.
- Retain selected tier, scope, settings, support-matrix check, estimate, pilot result, approval, and planned review date in the deployment record.
Business example¶
A team needs runtime protection for 120 Azure and Arc-enabled production servers but only posture visibility for a separate development subscription. It enables the selected Defender for Servers tier on a 12-server pilot, confirms the extension and MDE device coverage, and compares the resulting bill with its estimate. It then applies the plan at the production management-group scope and sets a budget alert before expanding the Arc rollout.