Skip to content

Commit 5e25372

Browse files
Merge pull request #16856 from alkohli/secadvisor
Section on MS Defender Antivirus added - Pulled from Carlos' PR
2 parents 732ad64 + 4161f29 commit 5e25372

File tree

1 file changed

+13
-2
lines changed

1 file changed

+13
-2
lines changed

azure-local/concepts/security-features.md

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@ For more information, see the full [List of option rules](/windows/security/appl
8888
Allow rules in the base policy allow all Microsoft components delivered by the OS and the cloud deployments to be trusted. Deny rules block user mode applications and kernel components considered unsafe for the security posture of the solution.
8989

9090
> [!NOTE]
91-
> The Allow and Deny rules in the base policy are updated regularly to improve product funtionality and maximize protection of your solution.
91+
> The Allow and Deny rules in the base policy are updated regularly to improve product functionality and maximize protection of your solution.
9292
9393
To learn more about Deny rules, see:
9494

@@ -134,7 +134,7 @@ In this release, the following capabilities are enabled:
134134
- The ability to monitor and alert whether certificates are still valid.
135135

136136
> [!NOTE]
137-
> Secret creation and rotation operations take about ten minutes to complete, depending on the size of the system.
137+
> Secret creation and rotation operations take about 10 minutes to complete, depending on the size of the system.
138138
139139
For more information, see [Manage secrets rotation](../manage/manage-secrets-rotation.md).
140140

@@ -154,6 +154,17 @@ The syslog forwarder in Azure Local supports various configurations based on whe
154154

155155
For more information, see [Manage syslog forwarding](../manage/manage-syslog-forwarding.md).
156156

157+
## Microsoft Defender Antivirus
158+
159+
Azure Local comes with Microsoft Defender Antivirus enabled and configured by default. We strongly recommend that you use Microsoft Defender Antivirus with your Azure Local instances. Microsoft Defender Antivirus provides real-time protection, cloud-delivered protection, and automatic sample submission.
160+
161+
Although we recommend using Microsoft Defender Antivirus for Azure Local, if you prefer third-party antivirus and security software, we advise selecting one that your Independent Software Vendor (ISV) has validated for Azure Local to minimize potential functionality issues.
162+
163+
For more information, see [Microsoft Defender Antivirus compatibility with other security products](/defender-endpoint/microsoft-defender-antivirus-compatibility).
164+
165+
> [!NOTE]
166+
> If you remove the Microsoft Defender Antivirus feature, leave the settings associated with the feature from the security baseline as-is. You don't need to remove these settings.
167+
157168
## Microsoft Defender for Cloud (preview)
158169

159170
Microsoft Defender for Cloud is a security posture management solution with advanced threat protection capabilities. It provides you with tools to assess the security status of your infrastructure, protect workloads, raise security alerts, and follow specific recommendations to remediate attacks and address future threats. It performs all these services at high speed in the cloud through autoprovisioning and protection with Azure services, with no deployment overhead.

0 commit comments

Comments
 (0)