Microsoft Azure has released the latest version (220.127.116.11) of the Azure Antimalware extension for Cloud Services (PaaS v1).
This release includes support for Guest Agent Family 5+ and has Windows Server 2016 Operating System enabled with Defender by default.
The new extension will only configure the policies in your Azure PaaS v1 nodes, as Defender is already enabled by default.
For Windows Server 2012 R2 and older versions, the extension will be working as is.
When you use the disable option, only the Excluded policies will be removed. There will not be any changes to Antimalware Engine status, Real Time Protection or Scan Type. This is an existing experience in both Windows Server 2012 R2 (and older) as well as Windows Server 2016.
You can configure antimalware extension using Azure portal, as seen in the figure below