Skip to content

Commit 00664e2

Browse files
committed
Update linux-preferences.md
1 parent 7650208 commit 00664e2

File tree

1 file changed

+35
-33
lines changed

1 file changed

+35
-33
lines changed

defender-endpoint/linux-preferences.md

Lines changed: 35 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -397,7 +397,7 @@ When this feature is enabled, Defender for Endpoint will scan files when their p
397397
|**Data type**|Boolean|n/a|
398398
|**Possible values**|false (default) <p> true|n/a|
399399
> [!NOTE]
400-
> Available in Defender for Endpoint version 101.23062.0010 or higher.
400+
> Available in Defender for Endpoint version `101.23062.0010` or later.
401401
402402
##### Configure scanning of file modify ownership events
403403

@@ -413,7 +413,7 @@ When this feature is enabled, Defender for Endpoint will scan files for which ow
413413
|**Possible values**|false (default) <p> true|n/a|
414414

415415
> [!NOTE]
416-
> Available in Defender for Endpoint version 101.23062.0010 or higher.
416+
> Available in Defender for Endpoint version `101.23062.0010` or later.
417417
418418
##### Configure scanning of raw socket events
419419

@@ -430,7 +430,7 @@ When this feature is enabled, Defender for Endpoint will scan network socket eve
430430
|**Possible values**|false (default) <p> true|n/a|
431431

432432
> [!NOTE]
433-
> Available in Defender for Endpoint version 101.23062.0010 or higher.
433+
> Available in Defender for Endpoint version `101.23062.0010` or later.
434434
435435

436436
### Cloud-delivered protection preferences
@@ -485,7 +485,7 @@ There are five values for setting cloud block level:
485485
|**Possible values**|`normal` (default) <p>`moderate` <p>`high` <p>`high_plus` <p>`zero_tolerance`|Not configured<br>Normal (default) <br>Moderate <br>High <br>High_Plus <br>Zero_Tolerance|
486486

487487
> [!NOTE]
488-
> Available in Defender for Endpoint version 101.56.62 or higher.
488+
> Available in Defender for Endpoint version `101.56.62` or later.
489489
490490
#### Enable / disable automatic sample submissions
491491

@@ -537,7 +537,7 @@ Determines whether module load events (file open events on shared libraries) are
537537
|**Key**|moduleLoad|*Not available*|
538538
|**Data type**|String|*n/a*|
539539
|**Possible values**|disabled (default) <p> enabled|*n/a*|
540-
|**Comments**|Available in Defender for Endpoint version 101.68.80 or higher.||
540+
|**Comments**|Available in Defender for Endpoint version 101.68.80 or later.||
541541

542542
#### Supplementary sensor configurations
543543

@@ -561,7 +561,7 @@ Determines whether file modify permissions events (`chmod`) are monitored.
561561
|**Key**|enableFilePermissionEvents|*Not available*|
562562
|**Data type**|String|*n/a*|
563563
|**Possible values**|disabled (default) <p> enabled|*n/a*|
564-
|**Comments**|Available in Defender for Endpoint version 101.23062.0010 or higher.|
564+
|**Comments**|Available in Defender for Endpoint version 101.23062.0010 or later.|
565565

566566
##### Configure monitoring of file modify ownership events
567567

@@ -575,7 +575,7 @@ Determines whether file modify ownership events (chown) are monitored.
575575
|**Key**|enableFileOwnershipEvents|*Not available*|
576576
|**Data type**|String|*n/a*|
577577
|**Possible values**|disabled (default) <p> enabled|*n/a*|
578-
|**Comments**|Available in Defender for Endpoint version 101.23062.0010 or higher.|
578+
|**Comments**|Available in Defender for Endpoint version 101.23062.0010 or later.|
579579

580580
##### Configure monitoring of raw socket events
581581

@@ -590,7 +590,7 @@ Determines whether network socket events involving creation of raw sockets / pac
590590
|**Key**|enableRawSocketEvent|*Not available*|
591591
|**Data type**|String|*n/a*|
592592
|**Possible values**|disabled (default) <p> enabled|*n/a*|
593-
|**Comments**|Available in Defender for Endpoint version 101.23062.0010 or higher.|
593+
|**Comments**|Available in Defender for Endpoint version 101.23062.0010 or later.|
594594

595595
##### Configure monitoring of boot loader events
596596

@@ -604,7 +604,7 @@ Determines whether boot loader events are monitored and scanned.
604604
|**Key**|enableBootLoaderCalls|*Not available*|
605605
|**Data type**|String|*n/a*|
606606
|**Possible values**|disabled (default) <p> enabled|*n/a*|
607-
|**Comments**|Available in Defender for Endpoint version 101.68.80 or higher.|
607+
|**Comments**|Available in Defender for Endpoint version `101.68.80` or later.|
608608

609609
##### Configure monitoring of ptrace events
610610

@@ -618,7 +618,7 @@ Determines whether ptrace events are monitored and scanned.
618618
|**Key**|enableProcessCalls|*Not available*|
619619
|**Data type**|String|*n/a*|
620620
|**Possible values**|disabled (default) <p> enabled|*n/a*|
621-
|**Comments**|Available in Defender for Endpoint version 101.68.80 or higher.|
621+
|**Comments**|Available in Defender for Endpoint version `101.68.80` or later.|
622622

623623
##### Configure monitoring of pseudofs events
624624

@@ -632,7 +632,7 @@ Determines whether pseudofs events are monitored and scanned.
632632
|**Key**|enablePseudofsCalls|*Not available*|
633633
|**Data type**|String|*n/a*|
634634
|**Possible values**|disabled (default) <p> enabled|*n/a*|
635-
|**Comments**|Available in Defender for Endpoint version 101.68.80 or higher.|
635+
|**Comments**|Available in Defender for Endpoint version `101.68.80` or later.|
636636

637637
##### Configure monitoring of module load events using eBPF
638638

@@ -646,7 +646,7 @@ Determines whether module load events are monitored using eBPF and scanned.
646646
|**Key**|enableEbpfModuleLoadEvents|*Not available*|
647647
|**Data type**|String|*n/a*|
648648
|**Possible values**|disabled (default) <p> enabled|*n/a*|
649-
|**Comments**|Available in Defender for Endpoint version 101.68.80 or higher.|
649+
|**Comments**|Available in Defender for Endpoint version `101.68.80` or later.|
650650

651651
#### Report AV Suspicious Events to EDR
652652

@@ -657,7 +657,7 @@ Determines whether suspicious events from Antivirus are reported to EDR.
657657
|**Key**|sendLowfiEvents|*Not available*|
658658
|**Data type**|String|*n/a*|
659659
|**Possible values**|disabled (default) <p> enabled|*n/a*|
660-
|**Comments**|Available in Defender for Endpoint version 101.23062.0010 or higher.|
660+
|**Comments**|Available in Defender for Endpoint version `101.23062.0010` or later.|
661661

662662
### Network protection configurations
663663

@@ -692,21 +692,21 @@ Determines whether ICMP events are monitored and scanned.
692692
|**Key**|disableIcmpInspection|*Not available*|
693693
|**Data type**|Boolean|*n/a*|
694694
|**Possible values**|`true` (default) <p>`false`|*n/a*|
695-
|**Comments**|Available in Defender for Endpoint version 101.23062.0010 or higher.||
695+
|**Comments**|Available in Defender for Endpoint version `101.23062.0010` or later.||
696696

697697
## Recommended configuration profile
698698

699699
To get started, we recommend the following configuration profile for your enterprise to take advantage of all protection features that Defender for Endpoint provides.
700700

701-
The following configuration profile will:
701+
The following configuration profile:
702702

703-
- Enable real-time protection (RTP)
704-
- Specify how the following threat types are handled:
703+
- Enables real-time protection (RTP)
704+
- Specifies how the following threat types are handled:
705705
- **Potentially unwanted applications (PUA)** are blocked
706706
- **Archive bombs** (file with a high compression rate) are audited to the product logs
707-
- Enable automatic security intelligence updates
708-
- Enable cloud-delivered protection
709-
- Enable automatic sample submission at `safe` level
707+
- Enables automatic security intelligence updates
708+
- Enables cloud-delivered protection
709+
- Enables automatic sample submission at `safe` level
710710

711711
### Sample profile
712712

@@ -815,32 +815,34 @@ The following configuration profile contains entries for all settings described
815815
When you run the `mdatp health` command for the first time, the value for the tag and group ID will be blank. To add tag or group ID to the `mdatp_managed.json` file, follow the below steps:
816816

817817
1. Open the configuration profile from the path `/etc/opt/microsoft/mdatp/managed/mdatp_managed.json`.
818-
2. Go down to the bottom of the file, where the `cloudService` block is located.
819-
3. Add the required tag or group ID as following example at the end of the closing curly bracket for the `cloudService`.
820818

821-
```JSON
822-
},
823-
"cloudService": {
819+
2. Go down to the bottom of the file, where the `cloudService` block is located.
820+
821+
3. Add the required tag or group ID as following example at the end of the closing curly bracket for the `cloudService`.
822+
823+
```JSON
824+
},
825+
"cloudService": {
824826
"enabled": true,
825827
"diagnosticLevel": "optional",
826828
"automaticSampleSubmissionConsent": "safe",
827829
"automaticDefinitionUpdateEnabled": true,
828830
"proxy": "http://proxy.server:port/"
829-
},
830-
"edr": {
831-
"groupIds":"GroupIdExample",
832-
"tags": [
831+
},
832+
"edr": {
833+
"groupIds":"GroupIdExample",
834+
"tags": [
833835
{
834836
"key": "GROUP",
835837
"value": "Tag"
836838
}
837839
]
838840
}
839-
}
840-
```
841+
}
842+
```
841843

842-
>[!NOTE]
843-
>Add the comma after the closing curly bracket at the end of the `cloudService` block. Also, make sure that there are two closing curly brackets after adding Tag or Group ID block (please see the above example). At the moment, the only supported key name for tags is `GROUP`.
844+
> [!NOTE]
845+
> Add the comma after the closing curly bracket at the end of the `cloudService` block. Also, make sure that there are two closing curly brackets after adding Tag or Group ID block (please see the above example). At the moment, the only supported key name for tags is `GROUP`.
844846
845847
## Configuration profile validation
846848

0 commit comments

Comments
 (0)