You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/enable-defender-for-endpoint.md
+2-1Lines changed: 2 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,8 @@ description: Learn how to deploy the Microsoft Defender for Endpoint integration
4
4
author: dcurwin
5
5
ms.author: dacurwin
6
6
ms.topic: how-to
7
-
ms.date: 02/14/2024
7
+
ms.date: 03/13/2024
8
+
#customer intent: As a user, I want to learn how to enable the Defender for Endpoint integration in Defender for Cloud so that I can protect my Azure, hybrid, and multicloud machines.
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/endpoint-protection-recommendations-technical.md
+18-4Lines changed: 18 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,10 +1,11 @@
1
1
---
2
-
title: Assessment checks for endpoint detection and response solutions (MMA)
3
-
description: How the endpoint protection solutions are discoveredand identified as healthy.
4
-
ms.topic: conceptual
2
+
title: Assessment checks for endpoint detection and response
3
+
description: How the endpoint protection solutions are discovered, identified, and maintained for optimal security.
4
+
ms.topic: concept-article
5
5
ms.author: dacurwin
6
6
author: dcurwin
7
-
ms.date: 02/13/2024
7
+
ms.date: 03/13/2024
8
+
#customer intent: As a reader, I want to understand the assessment checks for endpoint detection and response solutions so that I can ensure the security of my systems.
8
9
---
9
10
10
11
# Assessment checks for endpoint detection and response solutions (MMA)
@@ -22,6 +23,7 @@ Microsoft Defender for Cloud provides health assessments of [supported](supporte
22
23
23
24
## Windows Defender
24
25
26
+
The table explains the scenarios that lead Defender for Cloud to generate the following two recommendations for Windows Defender:
25
27
26
28
| Recommendation | Appears when |
27
29
|--|--|
@@ -30,40 +32,52 @@ Microsoft Defender for Cloud provides health assessments of [supported](supporte
30
32
31
33
## Microsoft System Center endpoint protection
32
34
35
+
The table explains the scenarios that lead Defender for Cloud to generate the following two recommendations for Microsoft System Center endpoint protection:
36
+
33
37
| Recommendation | Appears when |
34
38
|--|--|
35
39
|**Endpoint protection should be installed on your machines**| importing **SCEPMpModule ("$env:ProgramFiles\Microsoft Security Client\MpProvider\MpProvider.psd1")** and running **Get-MProtComputerStatus** results in **AMServiceEnabled = false**|
36
40
|**Endpoint protection health issues should be resolved on your machines**|**Get-MprotComputerStatus** runs and any of the following occurs: <br><br> At least one of the following properties is false: <br><br> - **AMServiceEnabled** <br> - **AntispywareEnabled** <br> - **RealTimeProtectionEnabled** <br> - **BehaviorMonitorEnabled** <br> - **IoavProtectionEnabled** <br> - **OnAccessProtectionEnabled** <br><br> If one or both of the following Signature Updates are greater or equal to 7: <br><br> - **AntispywareSignatureAge** <br> - **AntivirusSignatureAge**|
37
41
38
42
## Trend Micro
39
43
44
+
The table explains the scenarios that lead Defender for Cloud to generate the following two recommendations for Trend Micro:
45
+
40
46
| Recommendation | Appears when |
41
47
|--|--|
42
48
|**Endpoint protection should be installed on your machines**| any of the following checks aren't met: <br><br> - **HKLM:\SOFTWARE\TrendMicro\Deep Security Agent** exists <br> - **HKLM:\SOFTWARE\TrendMicro\Deep Security Agent\InstallationFolder** exists <br> - The **dsa_query.cmd** file is found in the Installation Folder <br> - Running **dsa_query.cmd** results with **Component.AM.mode: on - Trend Micro Deep Security Agent detected**|
43
49
44
50
## Symantec endpoint protection
45
51
52
+
The table explains the scenarios that lead Defender for Cloud to generate the following two recommendations for Symantec endpoint protection:
53
+
46
54
| Recommendation | Appears when |
47
55
|--|--|
48
56
|**Endpoint protection should be installed on your machines**| any of the following checks aren't met: <br> <br> - **HKLM:\Software\Symantec\Symantec Endpoint Protection\CurrentVersion\PRODUCTNAME = "Symantec Endpoint Protection"** <br> - **HKLM:\Software\Symantec\Symantec Endpoint Protection\CurrentVersion\public-opstate\ASRunningStatus = 1** <br> Or <br> - **HKLM:\Software\Wow6432Node\Symantec\Symantec Endpoint Protection\CurrentVersion\PRODUCTNAME = "Symantec Endpoint Protection"** <br> - **HKLM:\Software\Wow6432Node\Symantec\Symantec Endpoint Protection\CurrentVersion\public-opstate\ASRunningStatus = 1**|
49
57
| **Endpoint protection health issues should be resolved on your machines** | any of the following checks aren't met: <br> <br> - Check Symantec Version >= 12: Registry location: **HKLM:\Software\Symantec\Symantec Endpoint Protection\CurrentVersion" -Value "PRODUCTVERSION"** <br> - Check Real-Time Protection status: **HKLM:\Software\Wow6432Node\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\OnOff == 1** <br> - Check Signature Update status: **HKLM\Software\Symantec\Symantec Endpoint Protection\CurrentVersion\public-opstate\LatestVirusDefsDate <= 7 days** <br> - Check Full Scan status: **HKLM:\Software\Symantec\Symantec Endpoint Protection\CurrentVersion\public-opstate\LastSuccessfulScanDateTime <= 7 days** <br> - Find signature version number Path to signature version for Symantec 12: **Registry Paths+ "CurrentVersion\SharedDefs" -Value "SRTSP"** <br> - Path to signature version for Symantec 14: **Registry Paths+ "CurrentVersion\SharedDefs\SDSDefs" -Value "SRTSP"** <br><br> Registry Paths: <br> <br> - **"HKLM:\Software\Symantec\Symantec Endpoint Protection" + $Path;** <br> - **"HKLM:\Software\Wow6432Node\Symantec\Symantec Endpoint Protection" + $Path** |
50
58
51
59
## McAfee endpoint protection for Windows
52
60
61
+
The table explains the scenarios that lead Defender for Cloud to generate the following two recommendations for McAfee endpoint protection for Windows:
62
+
53
63
| Recommendation | Appears when |
54
64
|--|--|
55
65
|**Endpoint protection should be installed on your machines**| any of the following checks aren't met: <br><br> - **HKLM:\SOFTWARE\McAfee\Endpoint\AV\ProductVersion** exists <br> - **HKLM:\SOFTWARE\McAfee\AVSolution\MCSHIELDGLOBAL\GLOBAL\enableoas = 1**|
56
66
|**Endpoint protection health issues should be resolved on your machines**| any of the following checks aren't met: <br> <br> - McAfee Version: **HKLM:\SOFTWARE\McAfee\Endpoint\AV\ProductVersion >= 10** <br> - Find Signature Version: **HKLM:\Software\McAfee\AVSolution\DS\DS -Value "dwContentMajorVersion"** <br> - Find Signature date: **HKLM:\Software\McAfee\AVSolution\DS\DS -Value "szContentCreationDate" >= 7 days** <br> - Find Scan date: **HKLM:\Software\McAfee\Endpoint\AV\ODS -Value "LastFullScanOdsRunTime" >= 7 days**|
57
67
58
68
## McAfee Endpoint Security for Linux Threat Prevention
59
69
70
+
The table explains the scenarios that lead Defender for Cloud to generate the following two recommendations for McAfee Endpoint Security for Linux Threat Prevention:
71
+
60
72
| Recommendation | Appears when |
61
73
|--|--|
62
74
|**Endpoint protection should be installed on your machines**| any of the following checks aren't met: <br> <br> - File **/opt/McAfee/ens/tp/bin/mfetpcli** exists <br> - **"/opt/McAfee/ens/tp/bin/mfetpcli --version"** output is: **McAfee name = McAfee Endpoint Security for Linux Threat Prevention and McAfee version >= 10**|
63
75
|**Endpoint protection health issues should be resolved on your machines**| any of the following checks aren't met: <br> <br> - **"/opt/McAfee/ens/tp/bin/mfetpcli --listtask"** returns **Quick scan, Full scan** and both of the scans <= 7 days <br> - **"/opt/McAfee/ens/tp/bin/mfetpcli --listtask"** returns **DAT and engine Update time** and both of them <= 7 days <br> - **"/opt/McAfee/ens/tp/bin/mfetpcli --getoasconfig --summary"** returns **On Access Scan** status |
64
76
65
77
## Sophos Antivirus for Linux
66
78
79
+
The table explains the scenarios that lead Defender for Cloud to generate the following two recommendations for Sophos Antivirus for Linux:
80
+
67
81
| Recommendation | Appears when |
68
82
|--|--|
69
83
|**Endpoint protection should be installed on your machines**| any of the following checks aren't met: <br> <br> - File **/opt/sophos-av/bin/savdstatus** exits or search for customized location **"readlink $(which savscan)"** <br> - **"/opt/sophos-av/bin/savdstatus --version"** returns Sophos name = **Sophos Anti-Virus and Sophos version >= 9**|
0 commit comments