
Explanation:

In Microsoft Defender for Endpoint , the Live Response feature enables security analysts to remotely connect to devices (including servers) via a secure shell session directly from the Microsoft 365 D efender portal . This feature allows real-time investigation, evidence collection, and remediation commands without requiring direct network access to the device.
To enable this capability for Windows servers , you must first enable the "Live Response for Se rvers" advanced feature within Defender for Endpoint settings. Microsoft's documentation explicitly states that this setting allows remote shell access to onboarded Windows Server devices, which is disabled by default for security reasons.
Once the advance d feature is enabled, Live Response permissions and functionality are managed at the device group level. Device groups in Defender for Endpoint are typically configured using device tags , which classify and organize endpoints (e.g., by department, OS type, or role). Tag-based grouping allows administrators to apply policies or features (like Live Response) efficiently to specific sets of devices, such as only production servers.
Alternative options such as "Automation level" or "device value" are unrelated - automation level controls auto-remediation, while device value assigns importance for alert prioritization.
Thus, the correct configuration steps are:
* Enable Live Response for Servers under advanced features.
* Apply the configuration to the target device group identified by a device tag .
# Final Answer:
* Advanced feature: Live Response for Servers
* For the device group: A device tag