Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Best Antivirus for Windows Server: Why Desktop Licences Will Not Do

11 min read Updated October 5, 2026 Antivirus Comparisons

Fix it now

Desktop antivirus is licensed for client operating systems and brings desktop assumptions to a server: prompts nobody is logged in to see, and no idea what an Active Directory database is. Buy server-licensed protection, and plan the exclusions before the agent goes into production.

  1. Buy Bitdefender GravityZone Cloud and Server Security for a mixed physical and virtual estate. Bitdefender describes it as protecting Linux and Windows servers and virtual desktops with a featherweight agent that offloads scanning to dedicated Security Virtual Appliances, hypervisor-agnostic across VMware, Nutanix, Citrix, AWS, Azure and Google Cloud.
  2. Buy ESET Server Security if your workstations already run ESET PROTECT – ESET includes Server Security in the PROTECT Entry bundle, so servers and desktops stay in one console.
  3. Buy the Microsoft Defender for Business servers add-on if you are already on Business Premium or standalone Defender for Business. Microsoft licenses it per server instance for up to 60 servers.
  4. Do not assume Sophos endpoint licensing covers servers. Sophos states Windows Server requires a separate Sophos Workload Protection subscription.
  5. Never put a consumer suite on a server. It breaches the licence, it will not be supported, and it will eventually break something at a bad hour.
  6. Apply the documented role exclusions before you leave anything running unattended, taking the paths from the vendor and Microsoft documentation for your version rather than from a list in an article.

Bitdefender does not sell a product called GravityZone Security for Servers. The server and workload product is GravityZone Cloud and Server Security; check the name on your quote.

If the licensing question is what you came for, that is settled. Below is why Defender’s automatic exclusions are narrower than most people think, and what to exclude role by role.

Why it happens

The licensing point is simple. Home and small-business desktop products are sold for client operating systems and vendors write that into the terms. Installing one on Windows Server is unlicensed, will not be supported when you telephone about it, and is the first thing an auditor or an insurer’s questionnaire looks for.

The technical point is the one that costs you a weekend. Server products assume no interactive session, so decisions come from policy rather than a dialogue box. They throttle scanning against server workloads instead of assuming a user is waiting, and they are licensed per operating system instance, which is how you will be counting your estate anyway.

Virtualisation adds a third reason and it is the one with real money in it. Twenty guests scanning an identical operating system on the same storage generates twenty times the input and output for the same result. Bitdefender’s answer is explicit: a featherweight agent in the guest with scanning offloaded and centralised to dedicated Security Virtual Appliances, with multi-level caching and scan optimisation. On a consolidated host that is the difference between a scan nobody notices and a storage array that falls over on Sunday night.

You were told Defender on Windows Server handles its own exclusions

You have this one if A single file server or domain controller running the in-box product, with nobody having configured anything.

  1. Half true, and the half that is false is the dangerous one. Microsoft documents automatic exclusions for installed server roles on Windows Server 2016 and later, but states they apply only to real-time protection.
  2. They do not apply to quick, full or custom scans, to network inspection or to behaviour monitoring. For those you need custom exclusions, which always take precedence where they overlap.
  3. They are not supported on Windows Server 2012 R2, and they do not appear in the Windows Security app’s standard exclusion lists, so you cannot audit them by looking.

You are consolidating many guests onto shared storage

You have this one if A hypervisor host where every guest runs the same OS and the same scan schedule.

  1. Choose a product with an offloaded scanning design rather than staggering twenty full agents.
  2. Bitdefender publishes this architecture for GravityZone Cloud and Server Security; confirm on the quote how the appliance and the guests are counted, because it is licensed differently from one agent per machine.
  3. Stagger what remains across the cluster and keep it away from the backup window.

A third-party product went on and Defender did not come back off

You have this one if You removed the third-party suite and the server is now protected by neither, or by something in passive mode.

  1. Microsoft documents that Microsoft Defender Antivirus goes to passive mode when a non-Microsoft antivirus is installed, and warns that on certain versions such as Windows Server 2016 it may remain in passive mode or stay disabled after the third-party product is uninstalled.
  2. Check the state explicitly after any removal rather than assuming the switch happened.
  3. Microsoft also notes that on servers onboarded to Defender for Endpoint at platform version 4.18.2208.0 or later, the Turn off Windows Defender Group Policy setting places it into passive mode rather than disabling it.

Two of those three are configuration rather than purchase, which is the honest shape of this topic. The product decision takes an hour. Getting the exclusions and the post-removal state right decides whether the deployment is invisible or infamous.

Full reference

The realistic shortlist, as each vendor describes it

GravityZone Cloud and Server Security ESET Server Security Microsoft Defender on servers
What the vendor says it protects Linux and Windows servers and end-user instances such as virtual desktops, on-premises and multi-cloud Real-time protection for data passing through general servers; included in the ESET PROTECT Entry bundle Windows Server 2016 and later have Microsoft Defender Antivirus installed and functional by default
Console GravityZone, shared with workstations; an on-premises virtual appliance is documented ESET PROTECT, cloud or on-premises Microsoft Defender portal
Virtualisation approach Featherweight agent, scanning offloaded to Security Virtual Appliances; hypervisor-agnostic across VMware, Nutanix, Citrix, AWS, Azure and Google Cloud Agent per guest Agent per instance
Role exclusions Vendor documentation Vendor documentation Automatic for installed roles on 2016+, real-time protection only
Central management Included Included Defender for Business servers add-on, per server instance, up to 60 servers
Sophos, for comparison – – Sophos states Windows Server needs a separate Sophos Workload Protection subscription rather than the endpoint packages

What Defender’s automatic exclusions do and do not cover

Microsoft’s wording is that when you install a role on Windows Server 2016 or later, Microsoft Defender Antivirus includes automatic exclusions for the server role and any files added while installing it. The roles covered include Active Directory Domain Services, DHCP, DNS, File and Storage Services, Hyper-V, Print Server, Web Server (IIS) and Windows Server Update Services, plus the SYSVOL folder and File Replication Service.

The limits matter more than the list. Microsoft states the automatic exclusions apply only to real-time protection, and not to network inspection, behaviour monitoring, or quick, full and custom scans. To exclude those you must add custom exclusions, and a custom exclusion always wins where it duplicates an automatic one. Automatic exclusions are not supported on Windows Server 2012 R2, and neither built-in nor automatic exclusions appear in the Windows Security app’s standard lists – so a server that looks unconfigured may be, and one that looks configured may not be.

Scanning live database and virtual disk files can cause lock contention, replication failures and corruption. Before a scanner goes into production, plan exclusions for the Active Directory database and logs, SYSVOL and the DFSR database on domain controllers; mailbox databases, logs and transport queues on Exchange; data and log files and the temporary database on SQL Server; and virtual hard disks, checkpoints and cluster shared volume paths on Hyper-V hosts. Take the exact paths from the vendor and Microsoft documentation for your product version rather than from any article, including this one.

Exclusions are the actual work

  • Work role by role rather than server by server. A machine holding three roles needs all three sets.
  • Prefer process exclusions over path exclusions where the product supports them, because they are narrower.
  • Domain controllers: the directory database and its logs, SYSVOL, and the DFS Replication database and working folders.
  • File servers with replication: the replication staging and conflict folders, which are otherwise a reliable way to break DFSR.
  • Remember that on Defender the automatic set does not cover scheduled scans, so anything you rely on for real-time protection still needs a custom exclusion for scan time.
  • Stagger scans across a cluster, keep them away from the backup window, and check afterwards that they finished. A scan silently timing out for six months is common and invisible.

When Microsoft’s own answer is sufficient

For a single Windows file server in a Microsoft-managed estate, the in-box product plus correctly planned exclusions is a defensible position at no extra cost, and it is worth saying so plainly. Microsoft Defender Antivirus is installed and functional by default on Windows Server 2016 and later, so the protection is already there. What it lacks by default is central policy and reporting, which is what the Defender for Business servers add-on buys – licensed per server instance, for up to 60 servers, as an add-on to standalone Defender for Business or Microsoft 365 Business Premium.

The argument for a third-party product is what Microsoft does not manage well from one place at this size: hypervisor hosts where offloaded scanning changes the storage arithmetic, servers outside your tenant, and older Windows Server versions where the automatic exclusions do not apply at all.

Matching the product to the estate

  • Mixed physical and virtual servers, some Linux, one console with your desktops: GravityZone Cloud and Server Security.
  • Already running ESET PROTECT for workstations: ESET Server Security, which is in the Entry bundle already.
  • Already on Microsoft 365 Business Premium with fewer than 60 servers: the Defender for Business servers add-on, deployed rather than left at defaults.
  • Running Sophos on the desktops: budget for Sophos Workload Protection separately; the endpoint packages do not cover Windows Server.
  • A single small-business file server: the in-box Defender with planned exclusions is defensible. Add central management when you have more than one server to forget about.
  • Windows Server 2012 R2 still in service: automatic exclusions do not apply, so every exclusion is yours to write.

When a licence is the actual fix

If you need server-licensed protection that shares a console with your workstations, Bitdefender GravityZone Cloud and Server Security is the licence that covers it properly – and note the name, because Bitdefender does not sell anything called GravityZone Security for Servers. Arco supplies GravityZone licences and can work the count out with you: how many operating system instances you actually run once virtual machines are included, whether the offloaded Security Virtual Appliance design fits your hypervisor, and how server units sit alongside workstation units on the same subscription. If you are already on Microsoft 365 Business Premium and have fewer than 60 servers, we will tell you to price the Defender for Business servers add-on first.

Questions people ask about this

Is Microsoft Defender enough on a server?

For one Windows file server in a small estate it is a defensible baseline. Microsoft states it is installed and functional by default on Windows Server 2016 and later and applies automatic exclusions for installed roles. What it does not provide without a paid plan is central policy and reporting, and the automatic exclusions cover real-time protection only, so scheduled scans still need custom exclusions.

Do I licence per host or per virtual machine?

Almost always per operating system instance, so each guest counts even on one physical host. Designs that offload scanning to a security appliance are counted differently again – Bitdefender’s Security Virtual Appliance model is the example. Confirm it before ordering rather than after; this is the single most common costing mistake in server antivirus.

Can I use the same product on servers and desktops?

You can use the same platform and console, which is the point of GravityZone or ESET PROTECT. You cannot assume the same licence type: Sophos, for instance, states that Windows Server needs a separate Sophos Workload Protection subscription rather than the endpoint packages, and Microsoft needs the Defender for Business servers add-on.

What happens if I skip the exclusions?

Usually nothing for weeks, then something expensive: replication failures on a domain controller, an Exchange database dismounting under lock contention, DFSR reinitialising a replicated folder, or a SQL backup failing silently while the scanner holds the file. Plan them before the agent goes into production.

I removed a third-party product – is Defender protecting the server now?

Check rather than assume. Microsoft documents that Defender goes to passive mode when a non-Microsoft antivirus is installed, and warns that on some versions including Windows Server 2016 it can remain in passive mode or stay disabled after that product is uninstalled.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Do Phones and Tablets Deserve a Slot on Your Antivirus Licence? Review Antivirus for Schools and Charities: Licensing on a Restricted Budget Review AVG vs Avast: Two Brands, One Engine – So Which Licence Should You Buy? Review Norton Small Business vs Bitdefender Small Office Security Compared
โ† Back to Knowledge Base