For Servers deployment I would run Anti-Malware and Forensics with Learning mode configuration at first
Then I would add additional components, such as Anti-Ransomware and Behavioral Guard, Anti-Bot and Threat Emulation for the file system. I would start with learning mode configuration and create the relevant exclusions based on the server type and the component deployed
It is recommended that for servers deployment and policy configuration you will separate the policy rules that will provide you with more complete control over the servers deployment and policy
please read the following SK to learn more about learning mode to best practice and the configuration
“Always Be yourself, unless you can Be Batman, then always be Batman”