You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/integration-defender-for-endpoint.md
+12-16Lines changed: 12 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,7 +11,7 @@ ms.date: 12/14/2022
11
11
12
12
With Microsoft Defender for Servers, you gain access to and can deploy [Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/microsoft-defender-endpoint) to your server resources. Microsoft Defender for Endpoint is a holistic, cloud-delivered, endpoint security solution. The main features include:
13
13
14
-
- Risk-based vulnerability management and assessment
14
+
- Risk-based vulnerability management and assessment
15
15
- Attack surface reduction
16
16
- Behavioral based and cloud-powered protection
17
17
- Endpoint detection and response (EDR)
@@ -34,7 +34,7 @@ For more information about migrating servers from Defender for Endpoint to Defen
34
34
35
35
## Benefits of integrating Microsoft Defender for Endpoint with Defender for Cloud
36
36
37
-
[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/microsoft-defender-endpoint) protects your Windows and Linux machines whether they're hosted in Azure, hybrid clouds (on-premises), or multicloud environments.
37
+
[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/microsoft-defender-endpoint) protects your Windows and Linux machines whether they're hosted in Azure, hybrid clouds (on-premises), or multicloud environments.
38
38
39
39
The protections include:
40
40
@@ -72,7 +72,7 @@ Before you can enable the Microsoft Defender for Endpoint integration with Defen
72
72
73
73
- Ensure the machine is connected to Azure and the internet as required:
74
74
75
-
-**Azure virtual machines (Windows or Linux)** - Configure the network settings described in configure device proxy and internet connectivity settings: [Windows](/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet) or [Linux](/microsoft-365/security/defender-endpoint/linux-static-proxy-configuration).
75
+
-**Azure virtual machines (Windows or Linux)** - Configure the network settings described in configure device proxy and internet connectivity settings: [Windows](/microsoft-365/security/defender-endpoint/configure-proxy-internet) or [Linux](/microsoft-365/security/defender-endpoint/linux-static-proxy-configuration).
76
76
77
77
-**On-premises machines** - Connect your target machines to Azure Arc as explained in [Connect hybrid machines with Azure Arc-enabled servers](../azure-arc/servers/learn/quick-enable-hybrid-vm.md).
78
78
@@ -85,7 +85,7 @@ Before you can enable the Microsoft Defender for Endpoint integration with Defen
85
85
86
86
- For Linux servers, you must have Python installed. Python 3 is recommended for all distros, but is required for RHEL 8.x and Ubuntu 20.04 or higher. If needed, see Step-by-step Instructions for Installing Python on Linux.
87
87
88
-
- If you've moved your subscription between Azure tenants, some manual preparatory steps are also required. For details, [contact Microsoft support](https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/overview).
88
+
- If you've moved your subscription between Azure tenants, some manual preparatory steps are also required. For details, [contact Microsoft support](https://portal.azure.com/#view/Microsoft_Azure_Support/HelpAndSupportBlade/~/overview).
89
89
90
90
### Enable the integration
91
91
@@ -121,7 +121,7 @@ To deploy the MDE unified solution, you'll need to use the [REST API call](#enab
121
121
122
122
1. Select **Enable unified solution**.
123
123
1. Select **Save**.
124
-
1. In the confirmation prompt, verify the information and select **Enable** to continue.
124
+
1. In the confirmation prompt, verify the information and select **Enable** to continue.
125
125
126
126
:::image type="content" source="./media/integration-defender-for-endpoint/enable-unified-solution-result.png" alt-text="Confirming the use of the MDE unified solution for Windows Server 2012 R2 and 2016 machines":::
127
127
@@ -157,7 +157,6 @@ You'll deploy Defender for Endpoint to your Linux machines in one of two ways -
157
157
-[Existing users with Defender for Cloud's enhanced security features enabled and Microsoft Defender for Endpoint for Windows](#existing-users-with-defender-for-clouds-enhanced-security-features-enabled-and-microsoft-defender-for-endpoint-for-windows)
158
158
-[New users who never enabled the integration with Microsoft Defender for Endpoint for Windows](#new-users-who-never-enabled-the-integration-with-microsoft-defender-for-endpoint-for-windows)
159
159
160
-
161
160
##### Existing users with Defender for Cloud's enhanced security features enabled and Microsoft Defender for Endpoint for Windows
162
161
163
162
If you've already enabled the integration with **Defender for Endpoint for Windows**, you have complete control over when and whether to deploy Defender for Endpoint to your **Linux** machines.
@@ -175,7 +174,7 @@ If you've already enabled the integration with **Defender for Endpoint for Windo
175
174
176
175
1. Select **Enable for Linux machines**.
177
176
1. Select **Save**.
178
-
1. In the confirmation prompt, verify the information and select **Enable** to continue.
177
+
1. In the confirmation prompt, verify the information and select **Enable** to continue.
179
178
180
179
:::image type="content" source="./media/integration-defender-for-endpoint/enable-for-linux-result.png" alt-text="Confirming the integration between Defender for Cloud and Microsoft's EDR solution, Microsoft Defender for Endpoint for Linux":::
## Access the Microsoft Defender for Endpoint portal
256
255
257
-
1. Ensure the user account has the necessary permissions. Learn more in [Assign user access to Microsoft Defender Security Center](/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access).
258
-
259
-
1. Check whether you have a proxy or firewall that is blocking anonymous traffic. The Defender for Endpoint sensor connects from the system context, so anonymous traffic must be permitted. To ensure unhindered access to the Defender for Endpoint portal, follow the instructions in [Enable access to service URLs in the proxy server](/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet#enable-access-to-microsoft-defender-atp-service-urls-in-the-proxy-server).
256
+
1. Ensure the user account has the necessary permissions. Learn more in [Assign user access to Microsoft Defender Security Center](/microsoft-365/security/defender-endpoint/assign-portal-access).
260
257
261
-
1.Open the [Defender for Endpoint Security Center portal](https://securitycenter.windows.com/). Learn more about the portal's features and icons, in [Defender for Endpoint Security Center portal overview](/windows/security/threat-protection/microsoft-defender-atp/portal-overview).
258
+
1.Check whether you have a proxy or firewall that is blocking anonymous traffic. The Defender for Endpoint sensor connects from the system context, so anonymous traffic must be permitted. To ensure unhindered access to the Defender for Endpoint portal, follow the instructions in [Enable access to service URLs in the proxy server](/microsoft-365/security/defender-endpoint/configure-proxy-internet#enable-access-to-microsoft-defender-for-endpoint-service-urls-in-the-proxy-server).
262
259
260
+
1. Open the [Microsoft 365 Defender portal](https://security.microsoft.com/). Learn about [Microsoft Defender for Endpoint in Microsoft 365 Defender](/microsoft-365/security/defender/microsoft-365-security-center-mde).
263
261
264
262
## Send a test alert
265
263
@@ -294,7 +292,7 @@ For endpoints running Windows:
294
292
295
293
For endpoints running Linux:
296
294
297
-
1. Download the test alert tool fromhttps://aka.ms/LinuxDIY
295
+
1. Download the test alert tool from: <https://aka.ms/LinuxDIY>
298
296
1. Extract the contents of the zip file and execute this shell script:
299
297
300
298
`./mde_linux_edr_diy`
@@ -330,7 +328,7 @@ To remove the Defender for Endpoint solution from your machines:
330
328
331
329
### What's this "MDE.Windows" / "MDE.Linux" extension running on my machine?
332
330
333
-
In the past, Microsoft Defender for Endpoint was provisioned by the Log Analytics agent. When [we expanded support to include Windows Server 2019](release-notes-archive.md#microsoft-defender-for-endpoint-integration-with-azure-defender-now-supports-windows-server-2019-and-windows-10-on-windows-virtual-desktop-released-for-general-availability-ga) and Linux, we also added an extension to perform the automatic onboarding.
331
+
In the past, Microsoft Defender for Endpoint was provisioned by the Log Analytics agent. When [we expanded support to include Windows Server 2019](release-notes-archive.md#microsoft-defender-for-endpoint-integration-with-azure-defender-now-supports-windows-server-2019-and-windows-10-on-windows-virtual-desktop-released-for-general-availability-ga) and Linux, we also added an extension to perform the automatic onboarding.
334
332
335
333
Defender for Cloud automatically deploys the extension to machines running:
336
334
@@ -343,17 +341,15 @@ Defender for Cloud automatically deploys the extension to machines running:
343
341
> [!IMPORTANT]
344
342
> If you delete the MDE.Windows/MDE.Linux extension, it will not remove Microsoft Defender for Endpoint. to 'offboard', see [Offboard Windows servers.](/microsoft-365/security/defender-endpoint/configure-server-endpoints).
345
343
346
-
347
344
### I enabled the solution but the `MDE.Windows`/`MDE.Linux` extension isn't showing on my machine
348
345
349
346
If you enabled the integration, but still don't see the extension running on your machines:
350
347
351
-
1. You need to wait at least 12 hours to be sure there's an issue to investigate.
348
+
1. You need to wait at least 12 hours to be sure there's an issue to investigate.
352
349
1. If after 12 hours you still don't see the extension running on your machines, check that you've met [Prerequisites](#prerequisites) for the integration.
353
350
1. Ensure you've enabled the [Microsoft Defender for Servers](defender-for-servers-introduction.md) plan for the subscriptions related to the machines you're investigating.
354
351
1. If you've moved your Azure subscription between Azure tenants, some manual preparatory steps are required before Defender for Cloud will deploy Defender for Endpoint. For full details, [contact Microsoft support](https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/overview).
355
352
356
-
357
353
### What are the licensing requirements for Microsoft Defender for Endpoint?
358
354
359
355
Licenses for Defender for Endpoint for servers are included with **Microsoft Defender for Servers**.
0 commit comments