QuestionQ16

Manage and monitor security posture

You have a hybrid environment containing the following servers:

  • 50 Azure virtual machines running Windows Server 2019
  • 20 physical, on-premises servers running Windows Server 2019

All servers use a third-party antivirus solution that must stay active during a phased security rollout.

You need to onboard every server to Microsoft Defender for Endpoint by using a centralized deployment method. The solution must meet these requirements:

  • Endpoint detection and response (EDR) capabilities must be enabled.
  • Antivirus conflicts must be avoided during onboarding.

What should you do on the servers?

Explanation

For Windows Server, setting the ForceDefenderPassiveMode registry value to 1 before onboarding places Microsoft Defender Antivirus in passive mode. This avoids conflict with the active third-party antivirus while allowing Microsoft Defender for Endpoint EDR capabilities to operate.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!