Assuming the windows and Linux servers are end hosts and not doing any sort of bridging or switching, you would want BPDU guard (to ensure we don't accept body's from the server).
I would also set udld to alert only as it's less likely you'll see a loop on this interface from a unidirectional flow issue.
If they're designed to act as software switches, you'd want to look at root guard and potentially udld enforcement.