Enabling it at the workspace level doesn't enable just-in-time VM access, adaptive application controls, and network detections for Azure resources. In addition, the only Microsoft Defender plans available at the workspace level are Microsoft Defender for servers and Microsoft Defender for SQL servers on machines. Reference: https://docs.microsoft.com/en-us/azure/defender-for-cloud/enable-enhanced-security