Skip to content

Commit 9a82714

Browse files
Merge pull request #223617 from bmansheim/issue-101951
Implement changes from issue 101951
2 parents 74ded1b + a9148ca commit 9a82714

File tree

1 file changed

+12
-16
lines changed

1 file changed

+12
-16
lines changed

articles/defender-for-cloud/integration-defender-for-endpoint.md

Lines changed: 12 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.date: 12/14/2022
1111

1212
With Microsoft Defender for Servers, you gain access to and can deploy [Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/microsoft-defender-endpoint) to your server resources. Microsoft Defender for Endpoint is a holistic, cloud-delivered, endpoint security solution. The main features include:
1313

14-
- Risk-based vulnerability management and assessment
14+
- Risk-based vulnerability management and assessment
1515
- Attack surface reduction
1616
- Behavioral based and cloud-powered protection
1717
- Endpoint detection and response (EDR)
@@ -34,7 +34,7 @@ For more information about migrating servers from Defender for Endpoint to Defen
3434

3535
## Benefits of integrating Microsoft Defender for Endpoint with Defender for Cloud
3636

37-
[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/microsoft-defender-endpoint) protects your Windows and Linux machines whether they're hosted in Azure, hybrid clouds (on-premises), or multicloud environments.
37+
[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/microsoft-defender-endpoint) protects your Windows and Linux machines whether they're hosted in Azure, hybrid clouds (on-premises), or multicloud environments.
3838

3939
The protections include:
4040

@@ -72,7 +72,7 @@ Before you can enable the Microsoft Defender for Endpoint integration with Defen
7272

7373
- Ensure the machine is connected to Azure and the internet as required:
7474

75-
- **Azure virtual machines (Windows or Linux)** - Configure the network settings described in configure device proxy and internet connectivity settings: [Windows](/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet) or [Linux](/microsoft-365/security/defender-endpoint/linux-static-proxy-configuration).
75+
- **Azure virtual machines (Windows or Linux)** - Configure the network settings described in configure device proxy and internet connectivity settings: [Windows](/microsoft-365/security/defender-endpoint/configure-proxy-internet) or [Linux](/microsoft-365/security/defender-endpoint/linux-static-proxy-configuration).
7676

7777
- **On-premises machines** - Connect your target machines to Azure Arc as explained in [Connect hybrid machines with Azure Arc-enabled servers](../azure-arc/servers/learn/quick-enable-hybrid-vm.md).
7878

@@ -85,7 +85,7 @@ Before you can enable the Microsoft Defender for Endpoint integration with Defen
8585

8686
- For Linux servers, you must have Python installed. Python 3 is recommended for all distros, but is required for RHEL 8.x and Ubuntu 20.04 or higher. If needed, see Step-by-step Instructions for Installing Python on Linux.
8787

88-
- If you've moved your subscription between Azure tenants, some manual preparatory steps are also required. For details, [contact Microsoft support](https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/overview).
88+
- If you've moved your subscription between Azure tenants, some manual preparatory steps are also required. For details, [contact Microsoft support](https://portal.azure.com/#view/Microsoft_Azure_Support/HelpAndSupportBlade/~/overview).
8989

9090
### Enable the integration
9191

@@ -121,7 +121,7 @@ To deploy the MDE unified solution, you'll need to use the [REST API call](#enab
121121

122122
1. Select **Enable unified solution**.
123123
1. Select **Save**.
124-
1. In the confirmation prompt, verify the information and select **Enable** to continue.
124+
1. In the confirmation prompt, verify the information and select **Enable** to continue.
125125

126126
:::image type="content" source="./media/integration-defender-for-endpoint/enable-unified-solution-result.png" alt-text="Confirming the use of the MDE unified solution for Windows Server 2012 R2 and 2016 machines":::
127127

@@ -157,7 +157,6 @@ You'll deploy Defender for Endpoint to your Linux machines in one of two ways -
157157
- [Existing users with Defender for Cloud's enhanced security features enabled and Microsoft Defender for Endpoint for Windows](#existing-users-with-defender-for-clouds-enhanced-security-features-enabled-and-microsoft-defender-for-endpoint-for-windows)
158158
- [New users who never enabled the integration with Microsoft Defender for Endpoint for Windows](#new-users-who-never-enabled-the-integration-with-microsoft-defender-for-endpoint-for-windows)
159159

160-
161160
##### Existing users with Defender for Cloud's enhanced security features enabled and Microsoft Defender for Endpoint for Windows
162161

163162
If you've already enabled the integration with **Defender for Endpoint for Windows**, you have complete control over when and whether to deploy Defender for Endpoint to your **Linux** machines.
@@ -175,7 +174,7 @@ If you've already enabled the integration with **Defender for Endpoint for Windo
175174

176175
1. Select **Enable for Linux machines**.
177176
1. Select **Save**.
178-
1. In the confirmation prompt, verify the information and select **Enable** to continue.
177+
1. In the confirmation prompt, verify the information and select **Enable** to continue.
179178

180179
:::image type="content" source="./media/integration-defender-for-endpoint/enable-for-linux-result.png" alt-text="Confirming the integration between Defender for Cloud and Microsoft's EDR solution, Microsoft Defender for Endpoint for Linux":::
181180

@@ -254,12 +253,11 @@ URI: `https://management.azure.com/subscriptions/<subscriptionId>providers/Micro
254253

255254
## Access the Microsoft Defender for Endpoint portal
256255

257-
1. Ensure the user account has the necessary permissions. Learn more in [Assign user access to Microsoft Defender Security Center](/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access).
258-
259-
1. Check whether you have a proxy or firewall that is blocking anonymous traffic. The Defender for Endpoint sensor connects from the system context, so anonymous traffic must be permitted. To ensure unhindered access to the Defender for Endpoint portal, follow the instructions in [Enable access to service URLs in the proxy server](/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet#enable-access-to-microsoft-defender-atp-service-urls-in-the-proxy-server).
256+
1. Ensure the user account has the necessary permissions. Learn more in [Assign user access to Microsoft Defender Security Center](/microsoft-365/security/defender-endpoint/assign-portal-access).
260257

261-
1. Open the [Defender for Endpoint Security Center portal](https://securitycenter.windows.com/). Learn more about the portal's features and icons, in [Defender for Endpoint Security Center portal overview](/windows/security/threat-protection/microsoft-defender-atp/portal-overview).
258+
1. Check whether you have a proxy or firewall that is blocking anonymous traffic. The Defender for Endpoint sensor connects from the system context, so anonymous traffic must be permitted. To ensure unhindered access to the Defender for Endpoint portal, follow the instructions in [Enable access to service URLs in the proxy server](/microsoft-365/security/defender-endpoint/configure-proxy-internet#enable-access-to-microsoft-defender-for-endpoint-service-urls-in-the-proxy-server).
262259

260+
1. Open the [Microsoft 365 Defender portal](https://security.microsoft.com/). Learn about [Microsoft Defender for Endpoint in Microsoft 365 Defender](/microsoft-365/security/defender/microsoft-365-security-center-mde).
263261

264262
## Send a test alert
265263

@@ -294,7 +292,7 @@ For endpoints running Windows:
294292
295293
For endpoints running Linux:
296294
297-
1. Download the test alert tool from https://aka.ms/LinuxDIY
295+
1. Download the test alert tool from: <https://aka.ms/LinuxDIY>
298296
1. Extract the contents of the zip file and execute this shell script:
299297
300298
`./mde_linux_edr_diy`
@@ -330,7 +328,7 @@ To remove the Defender for Endpoint solution from your machines:
330328
331329
### What's this "MDE.Windows" / "MDE.Linux" extension running on my machine?
332330
333-
In the past, Microsoft Defender for Endpoint was provisioned by the Log Analytics agent. When [we expanded support to include Windows Server 2019](release-notes-archive.md#microsoft-defender-for-endpoint-integration-with-azure-defender-now-supports-windows-server-2019-and-windows-10-on-windows-virtual-desktop-released-for-general-availability-ga) and Linux, we also added an extension to perform the automatic onboarding.
331+
In the past, Microsoft Defender for Endpoint was provisioned by the Log Analytics agent. When [we expanded support to include Windows Server 2019](release-notes-archive.md#microsoft-defender-for-endpoint-integration-with-azure-defender-now-supports-windows-server-2019-and-windows-10-on-windows-virtual-desktop-released-for-general-availability-ga) and Linux, we also added an extension to perform the automatic onboarding.
334332
335333
Defender for Cloud automatically deploys the extension to machines running:
336334
@@ -343,17 +341,15 @@ Defender for Cloud automatically deploys the extension to machines running:
343341
> [!IMPORTANT]
344342
> If you delete the MDE.Windows/MDE.Linux extension, it will not remove Microsoft Defender for Endpoint. to 'offboard', see [Offboard Windows servers.](/microsoft-365/security/defender-endpoint/configure-server-endpoints).
345343
346-
347344
### I enabled the solution but the `MDE.Windows`/`MDE.Linux` extension isn't showing on my machine
348345
349346
If you enabled the integration, but still don't see the extension running on your machines:
350347
351-
1. You need to wait at least 12 hours to be sure there's an issue to investigate.
348+
1. You need to wait at least 12 hours to be sure there's an issue to investigate.
352349
1. If after 12 hours you still don't see the extension running on your machines, check that you've met [Prerequisites](#prerequisites) for the integration.
353350
1. Ensure you've enabled the [Microsoft Defender for Servers](defender-for-servers-introduction.md) plan for the subscriptions related to the machines you're investigating.
354351
1. If you've moved your Azure subscription between Azure tenants, some manual preparatory steps are required before Defender for Cloud will deploy Defender for Endpoint. For full details, [contact Microsoft support](https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/overview).
355352
356-
357353
### What are the licensing requirements for Microsoft Defender for Endpoint?
358354
359355
Licenses for Defender for Endpoint for servers are included with **Microsoft Defender for Servers**.

0 commit comments

Comments
 (0)